Stored cross site scripting via SVG file upload in Kiwi TCMS
CVE-2023-27489

7.6HIGH

Key Information:

Vendor

Kiwitcms

Status
Vendor
CVE Published:
29 March 2023

What is CVE-2023-27489?

Kiwi TCMS is an open-source test management system that accepts user-uploaded SVG files, which may contain executable JavaScript code. If these SVG files are accessed directly without being rendered within an HTML page, this code can be executed, leading to potential security risks. To mitigate this issue, a fix has been implemented in version 12.1, which includes the addition of the Content-Security-Policy HTTP header. This header effectively blocks inline JavaScript execution across modern web browsers. Users are strongly encouraged to update to the latest version to enhance their security posture. For those unable to upgrade, configuring the Content-Security-Policy header manually is recommended to protect against this vulnerability.

Affected Version(s)

Kiwi < 12.1

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.