Metasoft MetaCRM Unrestricted File Upload Vulnerability
Vulnerability
A critical vulnerability allowing unrestricted file uploads has been identified in Metasoft MetaCRM versions through 6.4.2. The issue resides in the file mobileupload.jsp, where the argument 'File' can be manipulated to upload arbitrary files. This vulnerability can be exploited remotely, and a public exploit is available.
Impact
Exploitation of this vulnerability allows for arbitrary file uploads, which could lead to server compromise and malicious activities.
Reproduction
The vulnerability can be reproduced by accessing the mobileupload.jsp file and manipulating the 'File' argument to upload arbitrary files. This can be done remotely, and the uploaded files could potentially be executed or processed by the server, leading to a compromise.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
