SQL Injection in MeterSphere Continuous Testing Platform
CVE-2025-53639

5.1MEDIUM

Key Information:

Vendor
CVE Published:
14 July 2025

What is CVE-2025-53639?

MeterSphere, an open-source continuous testing platform, is subject to a SQL injection vulnerability due to improper validation and sanitization of the sortField parameter in specific API endpoints. An attacker can exploit this by injecting malicious input, enabling the execution of arbitrary SQL statements. This exploitation may lead to the modification or deletion of critical database contents, posing a significant risk to the application's database integrity and overall availability. It is recommended to upgrade to version 3.6.5-lts or later to mitigate this vulnerability.

Affected Version(s)

metersphere < 3.6.5-lts

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-53639 : SQL Injection in MeterSphere Continuous Testing Platform