Executive brief
Metasoft MetaCRM, a customer relationship management platform, contains a security flaw that allows unauthorized users to upload files to the server. An attacker could use this to place malicious files on the system, potentially leading to a full compromise of the application and its data. This could result in the theft of sensitive customer information or a complete disruption of business operations.
Technical details
An unrestricted file upload vulnerability exists in Metasoft MetaCRM versions up to 6.4.0 Beta06. The flaw is located in the /business/qnaire/upload.jsp file, where the 'File' argument is not properly validated. A remote, unauthenticated attacker can exploit this by sending a specially crafted request to upload arbitrary files to the server. This can lead to remote code execution (RCE) if the attacker uploads a web shell or other executable script. A public exploit is available, and the vendor has reportedly not responded to disclosure attempts.
Affected products
- Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06
Timeline
- 2026-07-20: disclosed
- 2026-07-20: advisory