Junglewise Threat Intelligence

CVE-2026-8758: Metasoft MetaCRM unrestricted file upload in upload3.jsp

CVE-2026-8758 · Severity: high · CVSS 7.3 · Published 2026-05-17

Technologies: Metasoft MetaCRM. Vendors: Metasoft.

Executive brief

Metasoft MetaCRM, a customer relationship management platform, contains a security flaw that allows unauthorized users to upload files to the server. An attacker could use this to place malicious files on the system, potentially leading to a full compromise of the server and the customer data stored within it. This vulnerability can be exploited remotely without any user interaction or login credentials.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in Metasoft MetaCRM versions up to 6.4.0 Beta06. The flaw is located in the '/common/jsp/upload3.jsp' file and is triggered by manipulating the 'File' argument. Because the application fails to properly validate the type or content of uploaded files, a remote, unauthenticated attacker can upload arbitrary files to the web server. This typically allows for the execution of malicious scripts (such as a JSP web shell) in the context of the web server process. As of the advisory date, the vendor has not responded to disclosure attempts, and no official patch is available.

Affected products

  • Metasoft (美特软件) MetaCRM up to 6.4.0 Beta06

Timeline

  • 2026-05-17: advisory: Vulnerability disclosed via VulDB and NVD
  • 2026-05-17: disclosed: Public disclosure of the exploit details

References

Related threats