Unrestricted File Upload Vulnerability in Metasoft 美特软件 MetaCRM
CVE-2025-7880
Key Information:
- Vendor
Metasoft 美特软件
- Status
- Vendor
- CVE Published:
- 20 July 2025
Badges
What is CVE-2025-7880?
A significant vulnerability exists within Metasoft 美特软件 MetaCRM, specifically in the file handling functionality found in /business/common/sms/sendsms.jsp. This flaw allows for unrestricted file uploads, creating a potential attack vector for remote exploitation. Attackers can leverage this vulnerability to upload malicious files without adequate authentication or validation. Despite the vendor being informed about this issue, no acknowledgment or remediation response has been issued, increasing the urgency for affected users to address potential risks.
Affected Version(s)
MetaCRM 6.4.0
MetaCRM 6.4.1
MetaCRM 6.4.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved