SQL injection in MeterSphere - CVE-2025-53639
Published: April 24, 2026
MeterSphere
Detailed vulnerability description
The vulnerability allows a remote user to modify or delete database contents.
The vulnerability exists due to SQL injection in certain API endpoints when processing the sortField parameter in sorting requests. A remote user can supply crafted input in the sortField parameter to modify or delete database contents.
User interaction is required.