PT-2022-16065 · Unknown · Metersphere

Jorgectf

·

Published

2022-12-27

·

Updated

2023-01-05

·

CVE-2022-23544

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MeterSphere versions prior to 2.5.0
Description MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. A Server-Side request forgery in IssueProxyResourceService::getMdImageByUrl allows an attacker to access internal resources, as well as executing JavaScript code in the context of MeterSphere's origin by a victim of a reflected XSS.
Recommendations For versions prior to 2.5.0, update to version 2.5.0 to resolve the issue. As a temporary workaround, consider disabling the IssueProxyResourceService::getMdImageByUrl function until the update is applied.

Exploit

Fix

SSRF

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-23544
GHSA-VRV6-CG45-RMJJ

Affected Products

Metersphere