Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-25573 PoC — MeterSphere 安全漏洞

Source
Associated Vulnerability
Title:MeterSphere 安全漏洞 (CVE-2023-25573)
Description:MeterSphere是MeterSphere开源的一站式开源持续测试平台。 MeterSphere 1.20.20 lts 之前版本和 2.7.1之前版本存在安全漏洞,该漏洞源于文件/api/jmeter/download/files存在不正确的访问控制, 攻击者利用该漏洞可以下载任何文件。
Description
Metersphere is an open source continuous testing platform. In affected versions an improper access control vulnerability exists in `/api/jmeter/download/files`, which allows any user to download any file without authentication. This issue may expose all files available to the running process. This issue has been addressed in version 1.20.20 lts and 2.7.1
File Snapshot

id: CVE-2023-25573 info: name: Metersphere - Arbitrary File Read author: DhiyaneshDK severity ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.