MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. Versions prior to 2.5.1 allow users to upload a file, but do not validate the file name, which may lead to upload file to any path. The vulnerability has been fixed in v2.5.1. There are no workarounds.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-7584 MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. Versions prior to 2.5.1 allow users to upload a file, but do not validate the file name, which may lead to upload file to any path. The vulnerability has been fixed in v2.5.1. There are no workarounds.
Github GHSA Github GHSA GHSA-9p62-x3c5-hr5p Path Traversal In MeterSpere leads to upload file to any path
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 10 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-04-10T19:41:30.356Z

Reserved: 2022-11-28T17:27:19.999Z

Link: CVE-2022-46178

cve-icon Vulnrichment

Updated: 2024-08-03T14:31:44.422Z

cve-icon NVD

Status : Modified

Published: 2022-12-29T19:15:08.727

Modified: 2024-11-21T07:30:16.207

Link: CVE-2022-46178

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.