Unrestricted File Upload Vulnerability in Metasoft MetaCRM Software
CVE-2025-7878
Key Information:
- Vendor
Metasoft 美特软件
- Status
- Vendor
- CVE Published:
- 20 July 2025
Badges
What is CVE-2025-7878?
A vulnerability exists within the Metasoft MetaCRM platform that permits unrestricted file uploads through the file upload interface located at /common/jsp/upload2.jsp. By manipulating the file parameter, an attacker can upload arbitrary files, potentially leading to further exploitation of the web application and the underlying system. The vulnerability can be exploited remotely, putting systems at risk as public disclosure of the exploit increases the chances of attacks. The vendor has been notified of this issue but has not yet provided a response.
Affected Version(s)
MetaCRM 6.4.0
MetaCRM 6.4.1
MetaCRM 6.4.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved