CVE-2023-25156High· 7.5▾ TwilightNo protection against brute-force attacks on login page
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.9%
0.9% → 0.9%
Last analysed / modified upstream
Previous versions of Kiwi TCMS do not impose rate limits which makes it easier to attempt brute-force attacks against the login page.
Users should upgrade to v12.0 or later.
Users may install and configure a rate-limiting proxy in front of Kiwi TCMS. For example nginx.
kiwitcms < 12.0Upgrade to a patched release:
kiwitcms 12.0Connected by shared product, vendor, weakness, or advisory.
CVE-2023-25171High· 7.5Denial of service vulnerability on Password reset page
CVE-2023-32686Medium· 5.4kiwitcms vulnerable to stored XSS via unrestricted files upload
CVE-2023-36809High· 8.1Kiwi TCMS's misconfigured HTTP headers allow stored XSS execution with Firefox
CVE-2023-30613High· 7.7Unrestricted file upload in kiwi TCMS
CVE-2023-30544None· 0.0kiwi TCMS has possibility for user to update email address to unverified one
CVE-2023-27489High· 7.6Kiwi TCMS Stored Cross-site Scripting via SVG file