S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2022-23544 Scanner

CVE-2022-23544 scanner - SSRF vulnerability in MeterSphere

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.4k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-23544
6.1
CVSShigh
Exploitable remotely over the internet · no authentication required.

MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. Versions prior to 2.5.0 are subject to a Server-Side Request Forgery that leads to Cross-Site Scripting. A Server-Side request forgery in `IssueProxyResourceService::getMdImageByUrl` allows an attacker to access internal resources, as well as executing JavaScript code in the context of Metersphere's origin by a victim of a reflected XSS. This vulnerability has been fixed in v2.5.0. There are no known workarounds.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
metersphereby metersphere
< 2.5.0
Updated Aug 22, 2026View on NVD →
Detail

MeterSphere is an all-encompassing open-source platform designed for continuous testing, which includes functionalities for test management, interface testing, UI testing, and performance testing. It is employed by developers and QA engineers to streamline their testing processes, ensuring the delivery of robust and reliable software. The platform is built to support agile and DevOps practices, facilitating collaborative and efficient testing workflows. MeterSphere is particularly valued for its comprehensive approach to testing, providing users with a single solution to manage all aspects of their testing needs.

The identified SSRF vulnerability in MeterSphere versions prior to 2.5.0 allows attackers to send server-side requests to internal systems. This flaw can lead to unauthorized access to internal network resources, as well as enabling the execution of JavaScript code on the victim's browser due to a related reflected XSS vulnerability. This issue highlights the importance of validating and sanitizing all user-supplied input, especially in components that fetch resources based on URLs.

The vulnerability is located in the `IssueProxyResourceService::getMdImageByUrl` function, which fails to properly validate URLs before fetching them. This allows an attacker to construct a request that, when processed by MeterSphere, can access or interact with internal services that are not directly accessible from the internet. Additionally, this SSRF vulnerability is compounded by a reflected XSS issue, allowing for the execution of arbitrary JavaScript in the context of the application's domain.

If exploited, this vulnerability could lead to several security issues including internal network reconnaissance, data exfiltration, unauthorized access to sensitive information, and the potential for broader network compromise. The related XSS vulnerability could be used for phishing attacks, session hijacking, or other client-side exploits.

S4E offers a unique platform that not only identifies vulnerabilities like the SSRF in MeterSphere but also provides a comprehensive suite of tools for managing and mitigating cyber threats. By leveraging our platform, users can ensure their digital assets are secure against a broad spectrum of vulnerabilities. Our service enhances your cybersecurity posture by offering detailed insights, remediation guidance, and continuous monitoring, helping you to stay ahead of potential security breaches.

 

References

Solution Advice
  1. Immediately upgrade MeterSphere to version 2.5.0 or later to address the identified SSRF vulnerability.
  2. Conduct thorough input validation and sanitization to prevent malicious data from triggering unwanted actions in server-side components.
  3. Implement strict access controls and network segmentation to limit the potential impact of SSRF attacks on internal resources.
  4. Review and update security policies and practices to include checks for common web vulnerabilities, including SSRF and XSS, as part of your regular security audits.
  5. Educate development and security teams on the risks associated with SSRF and XSS vulnerabilities and encourage the adoption of secure coding practices.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.