MetaCRM 6.4.2 Remote Info Disclosure via /env.jsp (Metasoft)
CVE-2025-7874 Published on July 20, 2025

Metasoft 美特软件 MetaCRM env.jsp information disclosure
A vulnerability was found in Metasoft ???? MetaCRM up to 6.4.2. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /env.jsp. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD

Timeline

Advisory disclosed

VulDB entry created

VulDB entry last update

Weakness Types

What is an Information Disclosure Vulnerability?

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CVE-2025-7874 has been classified to as an Information Disclosure vulnerability or weakness.

What is an Authorization Vulnerability?

The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVE-2025-7874 has been classified to as an Authorization vulnerability or weakness.


Affected Versions

Metasoft 美特软件 MetaCRM:

Exploit Probability

EPSS
0.23%
Percentile
45.39%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.