CVE-2026-6629 is a SQL injection vulnerability affecting Metasoft MetaCRM versions up to 6.4.0, specifically in the Statement.executeUpdate function within the sql.jsp interface component. The flaw allows attackers to manipulate SQL arguments, enabling unauthorized database access and modification. This vulnerability has a HIGH severity rating with a CVSS score of 7.3, reflecting its broad accessibility and significant potential impact. The attack requires no authentication, can be executed remotely over the network, and presents minimal complexity for exploitation. While the exploit has been publicly disclosed and the vendor was notified early without response, current EPSS data indicates low prevalence of active exploitation at this time. However, the vulnerability appears on active security watch lists, suggesting ongoing community attention and potential for exploitation escalation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Metasoft 美特软件 | MetaCRM | 6.0, 6.1, 6.2, 6.3, 6.4.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.