Metersphere Improper Access Control (CVE-2023-25573)

Related Vulnerabilities: CVE-2023-25573  

Check Point Reference: CPAI-2023-1467 Date Published: 25 Jan 2024 Severity: High Last Updated: Thursday 25 January, 2024 Source: Industry Reference:CVE-2023-25573
Protection Provided by:

Security Gateway
R81, R80, R77, R75

Who is Vulnerable? Metersphere prior to 1.20.19
Metersphere from 2.0.0 up to 2.6.2 Vulnerability Description An improper access control vulnerability exists in Metersphere. Successful exploitation of this vulnerability could allow a remote attacker to read sensitive files on the affected system.