MeterSphere logic flaw allows retrieval of arbitrary user information
Vulnerability Description
MeterSphere is an open source continuous testing platform. Prior to version 2.10.25-lts, a logic flaw allows retrieval of arbitrary user information. This allows an unauthenticated attacker to log in to the system as any user. This issue has been patched in version 2.10.25-lts.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-62604
Credits & Attribution
No credits recorded in the NVD database.
References
More from metersphere
View All →Affected Vendor
metersphere
View all reports →