Impact
The vulnerability is a SQL injection flaw in the Statement.executeUpdate method of the sql.jsp interface of Metasoft 美特软件 MetaCRM. By manipulating the sql argument, an attacker can inject arbitrary SQL code through a remote request, potentially compromising the confidentiality and integrity of the underlying database. The weakness is classified under CWE-74 and CWE-89, indicating problematic input handling and SQL injection.
Affected Systems
All installations of Metasoft 美特软件 MetaCRM versions up to and including 6.4.0 are affected. No specific version beyond 6.4.0 has been identified as patched, so any deployment within that range remains vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity vulnerability. The EPSS score is not available, so the current exploitation probability is unknown, but the vulnerability has been publicly disclosed and may be used by attackers. It is not listed in CISA's KEV catalog. Remote exploitation is possible, with no obvious local privilege or authenticated prerequisites mentioned, so unprivileged remote users could potentially exploit the flaw.
OpenCVE Enrichment