CVE-2025-8516 | Kingdee Cloud-Starry-Sky Enterprise Edition up to 8.2 IIS-K3CloudMiniApp FileUploadAction.class filePath path traversal
A vulnerability, which was classified as problematic, has been found in Kingdee Cloud-Starry-Sky Enterprise Edition up to 8.2. This issue affects the function BaseServiceFactory.getFileUploadService.deleteFileAction of the file K3Cloud\BBCMallSite\WEB-INF\lib\Kingdee.K3.O2O.Base.WebApp.jar!\kingdee\k3\o2o\base\webapp\action\FileUploadAction.class of the component IIS-K3CloudMiniApp. The manipulation of the argument filePath leads to path traversal.
This vulnerability is documented as CVE-2025-8516. The attack can be initiated remotely. Additionally, an exploit exists.
It is suggested to install a patch to address this issue.
The vendor recommends as a short-term measure to "[t]emporarily disable external network access to the Kingdee Cloud Galaxy Retail System or set up an IP whitelist for access control." The long-term remediation will be: "Install the security patch provided by the Starry Sky system, with the specific solutions being: i) Adding authentication to the vulnerable CMKAppWebHandler.ashx interface; ii) Removing the file reading function."