Metasoft MetaCRM Unrestricted File Upload Vulnerability

Vulnerability

A critical vulnerability allowing unrestricted file uploads has been identified in Metasoft MetaCRM versions through 6.4.2. The issue resides in the file mobileupload.jsp, where the argument 'File' can be manipulated to upload arbitrary files. This vulnerability can be exploited remotely, and a public exploit is available.

Impact

Exploitation of this vulnerability allows for arbitrary file uploads, which could lead to server compromise and malicious activities.

Reproduction

The vulnerability can be reproduced by accessing the mobileupload.jsp file and manipulating the 'File' argument to upload arbitrary files. This can be done remotely, and the uploaded files could potentially be executed or processed by the server, leading to a compromise.

Added: Jul 20, 2025, 9:17 AM
Updated: Jul 20, 2025, 9:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
0.0
relevance
0.3
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.