High severity7.4NVD Advisory· Published Dec 29, 2022· Updated Jun 17, 2026
CVE-2022-46178
CVE-2022-46178
Description
MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. Versions prior to 2.5.1 allow users to upload a file, but do not validate the file name, which may lead to upload file to any path. The vulnerability has been fixed in v2.5.1. There are no workarounds.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
io.metersphere:metersphereMaven | < 2.5.1 | 2.5.1 |
Affected products
2- Range: < v2.5.1
Patches
Vulnerability mechanics
References
5- github.com/metersphere/metersphere/security/advisories/GHSA-9p62-x3c5-hr5pnvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-9p62-x3c5-hr5pghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-46178ghsaADVISORY
- github.com/metersphere/metersphere/blob/v2.5.0/framework/sdk-parent/sdk/src/main/java/io/metersphere/commons/utils/FileUtils.javaghsaWEB
- github.com/metersphere/metersphere/releases/tag/v2.5.1ghsaWEB
News mentions
0No linked articles in our index yet.