{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/metasoft/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-16324"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MetaCRM (up to 6.4.0 Beta06)"],"_cs_severities":["high"],"_cs_tags":["cve","rce","unrestricted-upload","web-vulnerability","metacrm","metasystem"],"_cs_type":"advisory","_cs_vendors":["Metasoft"],"content_html":"\u003cp\u003eThe vulnerability, identified as CVE-2026-16324, affects Metasoft 美特软件 MetaCRM versions up to 6.4.0 Beta06. This flaw, classified as an unrestricted file upload, resides within an unknown function associated with the \u003ccode\u003e/business/qnaire/upload.jsp\u003c/code\u003e file. Attackers can remotely exploit this by manipulating the 'File' argument in an HTTP request, allowing arbitrary files, such as webshells, to be uploaded to the server. The public availability of an exploit significantly escalates the threat, as it enables adversaries to gain initial access, achieve persistent remote code execution, and potentially compromise the underlying system. Despite early disclosure, the vendor has not provided any response or patch, leaving affected organizations exposed to potential severe data breaches or system control loss.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003eReconnaissance \u0026amp; Vulnerability Identification\u003c/strong\u003e: An attacker identifies a Metasoft MetaCRM instance running a vulnerable version (up to 6.4.0 Beta06) that exposes the \u003ccode\u003e/business/qnaire/upload.jsp\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ePayload Preparation\u003c/strong\u003e: The attacker crafts a malicious file, such as a JSP webshell, designed to execute arbitrary commands on the server.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eMalicious File Upload\u003c/strong\u003e: The attacker sends a crafted HTTP POST request to the \u003ccode\u003e/business/qnaire/upload.jsp\u003c/code\u003e endpoint, manipulating the 'File' argument to include the malicious payload.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUnrestricted Upload Exploitation\u003c/strong\u003e: The vulnerable MetaCRM application processes the request, failing to properly validate the uploaded file type or content, leading to the successful placement of the malicious file on the server.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eWebshell Deployment\u003c/strong\u003e: The uploaded malicious file (e.g., \u003ccode\u003eshell.jsp\u003c/code\u003e) is now accessible via a direct URL on the MetaCRM server.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eRemote Code Execution\u003c/strong\u003e: The attacker accesses the newly deployed webshell through a web browser or automated script, allowing them to execute arbitrary commands with the privileges of the web server process.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ePost-Exploitation\u003c/strong\u003e: With RCE, the attacker can establish persistence, exfiltrate sensitive data, move laterally within the network, or deploy further malicious payloads like ransomware.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-16324 allows remote attackers to upload arbitrary files, including webshells, onto the MetaCRM server. This provides the attacker with immediate remote code execution capabilities, leading to complete compromise of the affected system. The potential damage includes unauthorized access to sensitive business data, alteration or deletion of critical information, system downtime, and the deployment of additional malware such as ransomware or cryptocurrency miners. The vulnerability carries a CVSS v3.1 Base Score of 7.3 (High), indicating significant impact on confidentiality, integrity, and availability, and the public availability of an exploit drastically increases the likelihood of attack.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ePatch\u003c/strong\u003e: Immediately apply any available patches or updates from Metasoft addressing CVE-2026-16324 to MetaCRM instances running versions up to 6.4.0 Beta06.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeploy\u003c/strong\u003e: Deploy the Sigma rule \u0026quot;Detect CVE-2026-16324 Exploitation - Metasoft MetaCRM Unrestricted Upload\u0026quot; to your SIEM to detect attempts to exploit the \u003ccode\u003e/business/qnaire/upload.jsp\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eMonitor\u003c/strong\u003e: Enhance monitoring of web server logs for the \u003ccode\u003ewebserver\u003c/code\u003e logsource, specifically for HTTP POST requests to \u003ccode\u003e/business/qnaire/upload.jsp\u003c/code\u003e that might indicate anomalous file types or unusual query parameters.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eReview\u003c/strong\u003e: Conduct a thorough review of the \u003ccode\u003e/business/qnaire/upload.jsp\u003c/code\u003e functionality in MetaCRM for proper input validation and file type restrictions.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-20T22:18:08Z","date_published":"2026-07-20T22:18:08Z","id":"https://feed.craftedsignal.io/briefs/2026-07-metacrm-unrestricted-upload/","summary":"A high-severity vulnerability, CVE-2026-16324, exists in Metasoft MetaCRM up to version 6.4.0 Beta06, allowing remote attackers to perform unrestricted file uploads by manipulating the 'File' argument within the `/business/qnaire/upload.jsp` component, which can lead to webshell deployment and remote code execution; a public exploit is available, increasing the risk of attack.","title":"CVE-2026-16324: Metasoft MetaCRM Unrestricted File Upload Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-07-metacrm-unrestricted-upload/"}],"language":"en","title":"CraftedSignal Threat Feed - Metasoft","version":"https://jsonfeed.org/version/1.1"}