github.com
https://github.com/metersphere/metersphere/releases/tag/v2.9.0 CVE-2023-30550
MEDIUM
IDOR vulnerability exists in metersphere
Record summary
CVE-2023-30550 has a selected CVSS score of 6.8 (medium).
Description
MeterSphere is an open source continuous testing platform, covering functions such as test tracking, interface testing, UI testing, and performance testing. This IDOR vulnerability allows the administrator of a project to modify other projects under the workspace. An attacker can obtain some operating permissions. The issue has been fixed in version 2.9.0.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 29, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
metersphereBrowse metersphere / metersphere | CVE List | < 2.9.0 | affected |
References
2github.comConfirmation
https://github.com/metersphere/metersphere/security/advisories/GHSA-j5cq-cpw2-gp2q