PT-2023-22771 · Kiwi Tcms · Kiwi Tcms

Novemberdad

·

Publicado

2023-04-24

·

Atualizado

2023-05-03

·

CVE-2023-30544

CVSS v3.1

3.9

Baixa

VetorAV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kiwi TCMS versions prior to 12.2
Description Kiwi TCMS is an open source test management system. In versions prior to 12.2, users were able to update their email addresses via the My profile admin page without the ownership verification performed during account registration.
Recommendations For Kiwi TCMS versions prior to 12.2, upgrade to v12.2 or later to receive a patch. As a temporary workaround, consider restricting access to the My profile admin page until a patch is available. No other workarounds exist.

Exploit

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-30544
GHSA-7X6Q-3V3M-CWJG

Produtos afetados

Kiwi Tcms