Impact
A file upload functionality in Metasoft 美特软件 MetaCRM has an arbitrary upload flaw within the develop/systparam/softlogo/upload.jsp page. The flaw allows an external actor to upload any file type without restriction, potentially including scripts or web applications, and the uploaded content is stored in a web-accessible location. This can lead to code execution, defacement, or other attacks that compromise confidentiality, integrity, and availability, and the weakness maps to CWE‑434 (Unrestricted Upload of File with Dangerous Type) and CWE‑284 (Improper Access Control).
Affected Systems
The vulnerability affects the MetaCRM product from Metasoft 美特软件, specifically version 6.4.0, and targets the upload.jsp component located in the develop/systparam/softlogo subfolder. No other versions are listed as affected, but any deployment using the same component in that release is potentially vulnerable.
Risk and Exploitability
With a CVSS score of 5.3, the exploit is classified as moderate severity. The EPSS score is not available, so the current exploitation probability is uncertain, and the vulnerability is not listed in CISA's KEV catalog. The attack can be executed remotely without prior authentication, implying that an attacker who can reach the web interface may upload malicious content. Since the vendor has not responded to the disclosure and the exploit is publicly available, the likelihood of real-world use is elevated, warranting prompt mitigation.
OpenCVE Enrichment