Junglewise Threat Intelligence

CVE-2026-16324: Metasoft MetaCRM unrestricted file upload in upload.jsp

CVE-2026-16324 · Severity: high · CVSS 7.3 · Published 2026-07-20

Technologies: Metasoft MetaCRM. Vendors: Metasoft.

Executive brief

Metasoft MetaCRM, a customer relationship management platform, contains a security flaw that allows unauthorized users to upload files to the server. An attacker could use this to place malicious files on the system, potentially leading to a full compromise of the application and its data. This could result in the theft of sensitive customer information or a complete disruption of business operations.

Technical details

An unrestricted file upload vulnerability exists in Metasoft MetaCRM versions up to 6.4.0 Beta06. The flaw is located in the /business/qnaire/upload.jsp file, where the 'File' argument is not properly validated. A remote, unauthenticated attacker can exploit this by sending a specially crafted request to upload arbitrary files to the server. This can lead to remote code execution (RCE) if the attacker uploads a web shell or other executable script. A public exploit is available, and the vendor has reportedly not responded to disclosure attempts.

Affected products

  • Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06

Timeline

  • 2026-07-20: disclosed
  • 2026-07-20: advisory

References

Related threats