Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7x6q-3v3m-cwjg

Опубликовано: 24 апр. 2023
Источник: github
Github: Прошло ревью
CVSS3: 0

Описание

kiwi TCMS has possibility for user to update email address to unverified one

Impact

In previous versions of Kiwi TCMS users were able to update their email addresses via the "My profile" admin page. This page allowed them to change the email address registered with their account without the ownership verification performed during account registration.

Patches

With Kiwi TCMS v12.2 or later it is not possible to edit the email field associated with a user account!

Workarounds

No workaround exists.

References

Disclosed by @novemberdad.

Пакеты

Наименование

kiwitcms

pip
Затронутые версииВерсия исправления

< 12.2

12.2

EPSS

Процентиль: 65%
0.00494
Низкий

0 Low

CVSS3

Дефекты

CWE-283
CWE-863

Связанные уязвимости

CVSS3: 3.9
nvd
почти 3 года назад

Kiwi TCMS is an open source test management system. In versions of Kiwi TCMS prior to 12.2, users were able to update their email addresses via the `My profile` admin page. This page allowed them to change the email address registered with their account without the ownership verification performed during account registration. Operators of Kiwi TCMS should upgrade to v12.2 or later to receive a patch. No known workarounds exist.

EPSS

Процентиль: 65%
0.00494
Низкий

0 Low

CVSS3

Дефекты

CWE-283
CWE-863