Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-23544 PoC — MeterSphere 代码问题漏洞

Source
Associated Vulnerability
Title:MeterSphere 代码问题漏洞 (CVE-2022-23544)
Description:MeterSphere是MeterSphere开源的一站式开源持续测试平台。 MeterSphere 2.5.0之前版本存在代码问题漏洞,该漏洞源于存在服务器端请求伪造,导致反射型跨站脚本。
Description
MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. Versions prior to 2.5.0 are subject to a Server-Side Request Forgery that leads to Cross-Site Scripting. A Server-Side request forgery in `IssueProxyResourceService::getMdImageByUrl` allows an attacker to access internal resources, as well as executing JavaScript code in the context of Metersphere's origin by a victim of a reflected XSS. This vulnerability has been fixed in v2.5.0. There are no known workarounds.
File Snapshot

id: CVE-2022-23544 info: name: MeterSphere < 2.5.0 SSRF author: j4vaovo severity: medium de ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.