CVE-2023-37461

MEDIUM

Metersphere < 2.10.3 - Path Traversal and Arbitrary File Write via BelongType Parameter

Title source: llm
STIX 2.1

Description

Metersphere is an opensource testing framework. Files uploaded to Metersphere may define a `belongType` value with a relative path like `../../../../` which may cause metersphere to attempt to overwrite an existing file in the defined location or to create a new file. Attackers would be limited to overwriting files that the metersphere process has access to. This issue has been addressed in version 2.10.3. Users are advised to upgrade. There are no known workarounds for this vulnerability.

References (1)

Core 1
Core References

Scores

CVSS v3 5.6
EPSS 0.0054
EPSS Percentile 41.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
metersphere/metersphere < 2.10.3
Published Jul 17, 2023
Tracked Since Feb 18, 2026