CVE-2023-30544None· 0.0▾ Sunlitkiwi TCMS has possibility for user to update email address to unverified one
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.4%
Last analysed / modified upstream
In previous versions of Kiwi TCMS users were able to update their email addresses via the "My profile" admin page. This page allowed them to change the email address registered with their account without the ownership verification performed during account registration.
With Kiwi TCMS v12.2 or later it is not possible to edit the email field associated with a user account!
No workaround exists.
Disclosed by @novemberdad.
kiwitcms < 12.2Upgrade to a patched release:
kiwitcms 12.2Connected by shared product, vendor, weakness, or advisory.
CVE-2023-30613High· 7.7Unrestricted file upload in kiwi TCMS
CVE-2023-32686Medium· 5.4kiwitcms vulnerable to stored XSS via unrestricted files upload
CVE-2023-36809High· 8.1Kiwi TCMS's misconfigured HTTP headers allow stored XSS execution with Firefox
CVE-2023-25171High· 7.5Denial of service vulnerability on Password reset page
CVE-2023-25156High· 7.5No protection against brute-force attacks on login page
CVE-2023-27489High· 7.6Kiwi TCMS Stored Cross-site Scripting via SVG file