Weak password requirements in Kiwi TCMS
CVE-2023-22451

6.5MEDIUM

Key Information:

Vendor

Kiwitcms

Status
Vendor
CVE Published:
2 January 2023

What is CVE-2023-22451?

Kiwi TCMS, an open-source test management system, is susceptible to a vulnerability that allows users to choose easily guessable passwords when registering new accounts or changing their passwords. Versions 11.6 and earlier lack proper validation checks that ensure password strength, potentially compromising user accounts. The flaw is rectified in version 11.7, which enforces stricter password policies to enhance security. These improvements include prohibiting passwords that are overly similar to personal information, mandating a minimum length of 10 characters, disallowing commonly used passwords, and preventing entirely numeric passwords. Administrators have the option to reset passwords if they suspect weak selections have been made by users.

Affected Version(s)

Kiwi <= 11.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.