PT-2023-22771 · Kiwi Tcms · Kiwi Tcms

Novemberdad

·

Published

2023-04-24

·

Updated

2023-05-03

·

CVE-2023-30544

CVSS v3.1

3.9

Low

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kiwi TCMS versions prior to 12.2
Description Kiwi TCMS is an open source test management system. In versions prior to 12.2, users were able to update their email addresses via the My profile admin page without the ownership verification performed during account registration.
Recommendations For Kiwi TCMS versions prior to 12.2, upgrade to v12.2 or later to receive a patch. As a temporary workaround, consider restricting access to the My profile admin page until a patch is available. No other workarounds exist.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2023-30544
GHSA-7X6Q-3V3M-CWJG

Affected Products

Kiwi Tcms