An arbitrary file read vulnerability was found in Metersphere v1.15.4, where authenticated users can read any file on the server via the file download function.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Metersphere | Metersphere | 1.15.4 (including) | 1.15.4 (including) |
References