PT-2025-43364 · Unknown · Metersphere

Published

2025-10-22

·

Updated

2025-10-28

·

CVE-2025-62604

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MeterSphere versions prior to 2.10.25-lts
Description MeterSphere is a continuous testing platform. A logic flaw exists that allows retrieval of arbitrary user information. This flaw enables an unauthenticated attacker to log in to the system as any user.
Recommendations Update MeterSphere to version 2.10.25-lts or later.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-62604
GHSA-VJ5X-7374-RF96

Affected Products

Metersphere