Junglewise Threat Intelligence

CVE-2026-15514: Metasoft MetaCRM SQL injection in PHPRPC Remote Call Interface

CVE-2026-15514 · Severity: high · CVSS 7.3 · Published 2026-07-13

Technologies: Metasoft MetaCRM. Vendors: Metasoft.

Executive brief

Metasoft MetaCRM, a customer relationship management platform, contains a security vulnerability in its remote communication interface. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially allowing them to view, modify, or delete sensitive customer information. Because a public exploit is available and the vendor has not yet released a fix, organizations using this software are at immediate risk of data theft or service disruption.

Technical details

A SQL injection vulnerability exists in Metasoft MetaCRM versions up to and including 6.4.0 Beta06. The flaw is located within the RPCService.query function of the /customizemt/xkq/rpc.jsp file, which is part of the PHPRPC Remote Call Interface component. The vulnerability is triggered by insufficient sanitization of the 'phprpc_args' argument. A remote, unauthenticated attacker can exploit this by sending specially crafted RPC requests to execute arbitrary SQL queries against the backend database. Public exploit code has been released, increasing the likelihood of active exploitation. As of the advisory date, the vendor has not responded to disclosure attempts, and no official patch is available.

Affected products

  • Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06

Timeline

  • 2026-07-13: advisory: Initial disclosure by VulDB/NVD
  • 2026-07-13: disclosed: Public exploit made available

References

Related threats