CVE-2026-16324
Received Received - Intake

MetaCRM Unrestricted File Upload Vulnerability

Vulnerability report for CVE-2026-16324, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-20

Last updated on: 2026-07-20

Assigner: VulDB

Description

A vulnerability was identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. The impacted element is an unknown function of the file /business/qnaire/upload.jsp. Such manipulation of the argument File leads to unrestricted upload. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-20
Last Modified
2026-07-20
Generated
2026-07-21
AI Q&A
2026-07-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
metasoft metacrm to 6.4.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in Metasoft MetaCRM versions up to 6.4.0 Beta06. It involves an unrestricted file upload issue in the /business/qnaire/upload.jsp file due to improper handling of the 'File' argument. Attackers can exploit this to upload malicious files remotely without restrictions.

Detection Guidance

Detecting this vulnerability requires checking for unrestricted file upload capabilities in MetaCRM versions up to 6.4.0 Beta06. Inspect the /business/qnaire/upload.jsp endpoint for improper file validation. Look for unexpected file types or executable scripts being uploaded to the server.

Impact Analysis

An attacker could upload malicious files to the server, potentially leading to remote code execution, data theft, or system compromise. This could result in unauthorized access, data breaches, or disruption of services if the uploaded files are executed.

Compliance Impact

This vulnerability could lead to data breaches, violating GDPR's data protection requirements or HIPAA's safeguards for protected health information. Organizations may face legal penalties, reputational damage, and loss of customer trust if exploited.

Mitigation Strategies

Immediately upgrade MetaCRM to the latest version beyond 6.4.0 Beta06 if available. If no update exists, restrict access to /business/qnaire/upload.jsp via firewall rules or web server configuration. Implement strict file upload validation to block executable scripts and verify file types.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16324. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart