github.comConfirmation
https://github.com/metersphere/metersphere/security/advisories/GHSA-vcm3-5w3f-9f45 CVE-2025-53639
MEDIUM
Metersphere has SQL Injection Vulnerability in Sorting Field
Record summary
CVE-2025-53639 has a selected CVSS score of 5.1 (medium).
Description
MeterSphere is an open source continuous testing platform. Prior to version 3.6.5-lts, the sortField parameter in certain API endpoints is not properly validated or sanitized. An attacker can supply crafted input to inject and execute arbitrary SQL statements through the sorting functionality. This could result in modification or deletion of database contents, with a potential full compromise of the application’s database integrity and availability. Version 3.6.5-lts fixes the issue.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 15, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
metersphereBrowse metersphere / metersphere | CVE List | < 3.6.5-lts | affected |