github.com
https://github.com/kiwitcms/Kiwi CVE-2023-30544
LOW
Kiwi TCMS may allow user to update email address to unverified one
Record summary
CVE-2023-30544 has a selected CVSS score of 3.9 (low).
Description
Kiwi TCMS is an open source test management system. In versions of Kiwi TCMS prior to 12.2, users were able to update their email addresses via the `My profile` admin page. This page allowed them to change the email address registered with their account without the ownership verification performed during account registration. Operators of Kiwi TCMS should upgrade to v12.2 or later to receive a patch. No known workarounds exist.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 4, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | < 12.2 | affected | |
kiwitcmsBrowse PyPI / kiwitcms | GitHub Advisory | Before 12.2 · Fixed in 12.2 | affected |
References
6github.comConfirmation
https://github.com/kiwitcms/Kiwi/security/advisories/GHSA-7x6q-3v3m-cwjg huntr.comexploit
https://huntr.com/bounties/1714df73-e639-4d64-ab25-ced82dad9f85 huntr.dev
https://huntr.dev/bounties/1714df73-e639-4d64-ab25-ced82dad9f85 kiwitcms.org
https://kiwitcms.org/blog/kiwi-tcms-team/2023/04/23/kiwi-tcms-122 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-30544