Record summary

CVE-2022-23544 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.

Description

MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. Versions prior to 2.5.0 are subject to a Server-Side Request Forgery that leads to Cross-Site Scripting. A Server-Side request forgery in `IssueProxyResourceService::getMdImageByUrl` allows an attacker to access internal resources, as well as executing JavaScript code in the context of Metersphere's origin by a victim of a reflected XSS. This vulnerability has been fixed in v2.5.0. There are no known workarounds.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 11, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List< 2.5.0affected

Nuclei templates

1
ProjectDiscoveryMEDIUMMeterSphere < 2.5.0 SSRFCVSS 6.1

MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. Versions prior to 2.5.0 are subject to a Server-Side Request Forgery that leads to Cross-Site Scripting. A Server-Side request forgery in `IssueProxyResourceService::getMdImageByUrl` allows an attacker to access internal resources, as well as executing JavaScript code in the context of Metersphere's origin by a victim of a reflected XSS. This vulnerability has been fixed in v2.5.0. There are no known workarounds.

Impact

An attacker can exploit this vulnerability to send crafted requests to internal resources, potentially leading to unauthorized access or information disclosure.

Remediation

Upgrade MeterSphere to version 2.5.0 or later to mitigate the SSRF vulnerability.

WeaknessesCWE-918CWE-79
Authorsj4vaovo
Template tagscve2022cvemeterspheressrfoastxssvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:metersphere:metersphere:*:*:*:*:*:*:*:*
Shodan: html:"metersphere"
Shodan: http.html:"metersphere"
FOFA: title="MeterSphere"
FOFA: body="metersphere"
FOFA: title="metersphere"

Source: ProjectDiscovery

References

2