Back

HIGH

Path Traversal In MeterSpere allows file upload to any path

Published Dec 29, 2022

Description

MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. Versions prior to 2.5.1 allow users to upload a file, but do not validate the file name, which may lead to upload file to any path. The vulnerability has been fixed in v2.5.1. There are no workarounds.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Dec 29, 2022
Updated Apr 10, 2025
Reserved Nov 28, 2022

CISA Vulnrichment

Updated Apr 10, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_M
Published Dec 29, 2022
Updated Apr 10, 2025