An arbitrary file read vulnerability was found in Metersphere v1.15.4, where authenticated users can read any file on the server via the file download function.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Metersphere |
Metersphere |
1.15.4 (including) |
1.15.4 (including) |
References