Metasoft MetaCRM
- <= 6.4.0 Beta06
A vulnerability allowing unrestricted file upload has been identified in Metasoft MetaCRM versions through 6.4.0 Beta06. The issue resides in an unknown function of the file /common/jsp/upload3.jsp. This vulnerability can be exploited remotely, and the vendor has not responded to prior disclosure attempts.
Exploitation of this vulnerability allows for unrestricted file upload, which could lead to various attacks depending on the uploaded file's nature, such as executing malicious scripts or uploading harmful payloads.
To reproduce this vulnerability, send a POST request to /common/jsp/upload3.jsp with the key parameter set to 'file'. Include the file data in the request body, using 'multipart/form-data' as the content type. The request can be made using a web browser or a tool like Postman.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.