Kiwi TCMS unrestricted file upload vulnerability
CVE-2023-30613

9CRITICAL

Key Information:

Vendor

Kiwitcms

Status
Vendor
CVE Published:
24 April 2023

What is CVE-2023-30613?

Kiwi TCMS, an open-source test management system, previously allowed unrestricted file uploads, enabling attackers to upload executable files or scripts disguised as benign files. This lack of validation could lead users to execute malicious code unknowingly. With the release of version 12.2, Kiwi TCMS introduced enhanced upload validation controls that restrict file types and mitigate the risk of such attacks, blocking executable files and scripts embedded in any file type by default. Users are strongly encouraged to upgrade to this version to ensure better security and protect against potential exploitation.

Affected Version(s)

Kiwi < 12.2

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.