Kiwi TCMS has denial of service vulnerability on Password reset page
CVE-2023-25171
7.5HIGH
What is CVE-2023-25171?
Kiwi TCMS, an open-source test management system, allows attackers to exploit the password reset feature due to the absence of rate limits in versions prior to 12.0. This vulnerability can lead to denial-of-service attacks where an attacker, possessing knowledge of user email addresses, could flood the system with numerous password reset requests. This not only disrupts user experience but may also overwhelm SMTP resources. To mitigate this risk, users are strongly encouraged to upgrade to version 12.0 or higher. Alternatively, implementing a rate-limiting proxy or configuring limits on the email server may provide temporary relief from potential abuse.
Affected Version(s)
kiwi 12.0
