Kiwi TCMS has denial of service vulnerability on Password reset page
CVE-2023-25171

7.5HIGH

Key Information:

Vendor

Kiwitcms

Status
Vendor
CVE Published:
15 February 2023

What is CVE-2023-25171?

Kiwi TCMS, an open-source test management system, allows attackers to exploit the password reset feature due to the absence of rate limits in versions prior to 12.0. This vulnerability can lead to denial-of-service attacks where an attacker, possessing knowledge of user email addresses, could flood the system with numerous password reset requests. This not only disrupts user experience but may also overwhelm SMTP resources. To mitigate this risk, users are strongly encouraged to upgrade to version 12.0 or higher. Alternatively, implementing a rate-limiting proxy or configuring limits on the email server may provide temporary relief from potential abuse.

Affected Version(s)

kiwi 12.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.