Impact
A flaw in the /business/qnaire/upload.jsp component of the MetaCRM application allows attackers to manipulate the File parameter for unrestricted file upload; the CVE description does not explicitly state that uploaded files are executed, but the absence of validation is inferred to enable potential execution of malicious code, which could lead to remote code execution or other integrity and confidentiality violations.
Affected Systems
The vulnerable logic exists in Metasoft 美特软件 MetaCRM versions up to 6.4.0 Beta06. Any installation running one of these releases and exposing the upload.jsp endpoint is considered at risk; no specific build numbers are provided.
Risk and Exploitability
The CVSS score of 6.9 denotes a moderate severity, while the EPSS score of less than 1% indicates a low likelihood of widespread exploitation in the wild. However, a publicly available exploit is known and the attack can be launched remotely from the web interface without privileged context. The vulnerability is not listed in the CISA KEV catalog, but the lack of a vendor response suggests that the working‑path for remediation may remain unpatched for some time.
OpenCVE Enrichment