CVE Vulnerabilities

CVE-2021-45789

Published: Sep 29, 2022 | Modified: Sep 30, 2022
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An arbitrary file read vulnerability was found in Metersphere v1.15.4, where authenticated users can read any file on the server via the file download function.

Affected Software

Name Vendor Start Version End Version
Metersphere Metersphere 1.15.4 (including) 1.15.4 (including)

References