CVE-2023-50267 Information
Dec 29, 2023
cve
Description
MeterSphere is a one-stop open source continuous testing platform. Prior to 2.10.10-lts the authenticated attackers can update resources which don’t belong to him if the resource ID is known. This issue if fixed in 2.10.10-lts. There are no known workarounds.
Reference
https://github.com/metersphere/metersphere/security/advisories/GHSA-rcp4-c5p2-58v9
Share on: