PT-2022-16043 · Unknown · Metersphere

Fit2-Zhao

+1

·

Published

2022-12-14

·

Updated

2022-12-16

·

CVE-2022-23512

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions MeterSphere versions prior to 2.4.1
Description The issue concerns a Path Injection vulnerability in the ApiTestCaseService::deleteBodyFiles function, which takes a user-controlled string id and uses the provided value (testId) to construct a file path. This allows an attacker to target files on the server by adding specific parameters to the URL. The vulnerability has been fixed in version 2.4.1.
Recommendations For versions prior to 2.4.1, update to version 2.4.1 to resolve the issue. As a temporary workaround, consider restricting access to the ApiTestCaseService::deleteBodyFiles function to minimize the risk of exploitation. Avoid using user-controlled input for the testId variable in the affected API endpoint until the issue is resolved.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-23512
GHSA-5MWP-XW7P-5J27

Affected Products

Metersphere