PT-2025-30175 · Metacrm · Metacrm

Nu11

·

Published

2025-07-20

·

Updated

2025-08-27

·

CVE-2025-7873

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MetaCRM versions up to 6.4.2
Description A critical issue exists in MetaCRM due to a SQL injection vulnerability within the mcc login.jsp file. The workerid argument can be manipulated to exploit this issue, allowing for remote attacks. The exploit has been publicly disclosed.
Recommendations Versions prior to 6.4.2 should be updated.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-7873

Affected Products

Metacrm