Information Disclosure in MetaCRM by Metasoft
CVE-2025-7874

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
20 July 2025

Badges

👾 Exploit Exists

What is CVE-2025-7874?

A vulnerability has been identified in MetaCRM by Metasoft, specifically affecting version 6.4.2. The issue resides in the file /env.jsp, where improper authorization can lead to unauthorized information disclosure. This flaw can be exploited remotely, making it a significant risk for users of this software. Despite early notifications to the vendor, there has been no response regarding mitigation or patches, heightening the urgency for users to assess their security posture.

Affected Version(s)

MetaCRM 6.4.0

MetaCRM 6.4.1

MetaCRM 6.4.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

nu11 (VulDB User)
.