Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
metersphere vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2023-38494
MeterSphere is an open-source continuous testing platform. Prior to version 2.10.4 LTS, some interfaces of the Cloud version of MeterSphere do not have configuration permissions, and are sensitively leaked by attackers. Version 2.10.4 LTS contains a patch for this issue.
Metersphere Metersphere
4.5
CVSSv3
CVE-2023-30550
MeterSphere is an open source continuous testing platform, covering functions such as test tracking, interface testing, UI testing, and performance testing. This IDOR vulnerability allows the administrator of a project to modify other projects under the workspace. An attacker can...
Metersphere Metersphere
4.3
CVSSv3
CVE-2023-50267
MeterSphere is a one-stop open source continuous testing platform. before 2.10.10-lts, the authenticated attackers can update resources which don't belong to him if the resource ID is known. This issue if fixed in 2.10.10-lts. There are no known workarounds.
Metersphere Metersphere
8.8
CVSSv3
CVE-2023-35937
Metersphere is an open source continuous testing platform. In versions before 2.10.2 LTS, some key APIs in Metersphere lack permission checks. This allows ordinary users to execute APIs that can only be executed by space administrators or project administrators. For example, ordi...
Metersphere Metersphere
8.1
CVSSv3
CVE-2022-23512
MeterSphere is a one-stop open source continuous testing platform. Versions before 2.4.1 are vulnerable to Path Injection in ApiTestCaseService::deleteBodyFiles which takes a user-controlled string id and passes it to ApiTestCaseService, which uses the user-provided value (testId...
Metersphere Metersphere
6.1
CVSSv3
CVE-2022-23544
MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. Versions before 2.5.0 are subject to a Server-Side Request Forgery that leads to Cross-Site Scripting. A Server-Side request forgery...
Metersphere Metersphere
9.8
CVSSv3
CVE-2023-41878
MeterSphere is a one-stop open source continuous testing platform, covering functions such as test tracking, interface testing, UI testing and performance testing. The Selenium VNC config used in Metersphere is using a weak password by default, attackers can login to vnc and obta...
Metersphere Metersphere
6.5
CVSSv3
CVE-2023-25814
metersphere is an open source continuous testing platform. In versions before 2.7.1 a user who has permission to create a resource file through UI operations is able to append a path to their submission query which will be read by the system and displayed to the user. This allows...
Metersphere Metersphere
6.5
CVSSv3
CVE-2023-32699
MeterSphere is an open source continuous testing platform. Version 2.9.1 and prior are vulnerable to denial of service. ?The `checkUserPassword` method is used to check whether the password provided by the user matches the password saved in the database, and the `CodingUtil.md5` ...
Metersphere Metersphere
8.8
CVSSv3
CVE-2022-46178
MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. Versions before 2.5.1 allow users to upload a file, but do not validate the file name, which may lead to upload file to any path. Th...
Metersphere Metersphere
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3012
CVE-2024-30200
XXE
CVE-2023-24955
CVE-2023-42931
CVE-2024-29231
remote code execution
cross-site scripting
CVE-2024-0677
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »