Metasoft MetaCRM Deserialization Vulnerability in download.jsp Remote Code Execution

Vulnerability

A critical deserialization vulnerability has been identified in Metasoft MetaCRM versions through 6.4.2. The issue arises in the download.jsp file, specifically within the AnalyzeParam function, where the manipulation of the 'p' argument leads to unsafe deserialization of data. This vulnerability can be exploited remotely and has been publicly disclosed, with an available proof-of-concept exploit.

Impact

Exploitation of this vulnerability allows for deserialization of untrusted data, leading to remote code execution on the server.

Reproduction

The vulnerability can be reproduced by sending a request to the download.jsp page with a crafted 'p' parameter that exploits the deserialization flaw. This can be done manually or using an automated tool, such as a web vulnerability scanner or a custom script, that targets the specific deserialization vulnerability in the Fastjson library.

Added: Jul 20, 2025, 8:18 AM
Updated: Jul 20, 2025, 8:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
6.6
remediation
0.0
relevance
0.3
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.