CVE-2023-30544
Last modified
CVE-2023-30544 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Kiwi TCMS is an open source test management system. In versions of Kiwi TCMS prior to 12.2, users were able to update their email addresses via the `My profile` admin page. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
Kiwi TCMS is an open source test management system. In versions of Kiwi TCMS prior to 12.2, users were able to update their email addresses via the `My profile` admin page. This page allowed them to change the email address registered with their account without the ownership verification performed during account registration. Operators of Kiwi TCMS should upgrade to v12.2 or later to receive a patch. No known workarounds exist.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Kiwitcms | Kiwi Tcms | < 12.2 |
References
- https://huntr.dev/bounties/1714df73-e639-4d64-ab25-ced82dad9f85/Permissions Required
- https://huntr.dev/bounties/1714df73-e639-4d64-ab25-ced82dad9f85/Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-30544?
How severe is CVE-2023-30544?
How do I fix CVE-2023-30544?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-30538Discourse is an open source platform for community discussio…5.4
- CVE-2023-30539Nextcloud is a personal home server system. Depending on the…8.8
- CVE-2023-30540Nextcloud Talk is a chat, video & audio call extension for N…4.3
- CVE-2023-30541OpenZeppelin Contracts is a library for secure smart contrac…5.3
- CVE-2023-30542OpenZeppelin Contracts is a library for secure smart contrac…8.8
- CVE-2023-30543@web3-react is a framework for building Ethereum Apps . In a…5.7
- CVE-2023-30545PrestaShop is an Open Source e-commerce web application. Pri…6.5
- CVE-2023-30546Contiki-NG is an operating system for Internet of Things dev…7.5
- CVE-2023-30547vm2 is a sandbox that can run untrusted code with whiteliste…10
- CVE-2023-30548gatsby-plugin-sharp is a plugin for the gatsby framework whi…4.3
- CVE-2023-30549Apptainer is an open source container platform for Linux. Th…7.8
- CVE-2023-3055The Page Builder by AZEXO plugin for WordPress is vulnerable…4.3
Are you affected by CVE-2023-30544?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
