- EPSS -
- Veröffentlicht 17.09.2026 18:27:10
- Zuletzt bearbeitet 30.09.2026 17:51:56
Kiwi TCMS is an open source test management system. Prior to 16.0, the unauthenticated /init-db/ page handled by InitDBView in tcms/core/views.py remains reachable after initial setup and proxies repeated requests to Kiwi/manage.py migrate. The migra...
- EPSS 0.32%
- Veröffentlicht 15.09.2026 15:35:29
- Zuletzt bearbeitet 30.09.2026 17:51:56
Kiwi TCMS is an open source test management system. Prior to 16.1, TestCase.extra_link and TestPlan.extra_link accepted unsanitized user input and rendered stored values verbatim, creating an opportunity for cross-site scripting. Official Docker imag...
CVE-2026-54724
- EPSS 0.26%
- Veröffentlicht 15.09.2026 15:34:26
- Zuletzt bearbeitet 30.09.2026 17:51:56
Kiwi TCMS is an open source test management system. Prior to 16.1, the account confirmation endpoint accepted an unvalidated next parameter, allowing an unauthenticated attacker to create a URL on a trusted Kiwi TCMS hostname that redirects a victim ...
CVE-2023-36809
- EPSS 0.69%
- Veröffentlicht 05.07.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 08:10:38
Kiwi TCMS, an open source test management system allows users to upload attachments to test plans, test cases, etc. Versions of Kiwi TCMS prior to 12.5 had introduced changes which were meant to serve all uploaded files as plain text in order to prev...
CVE-2023-33977
- EPSS 0.87%
- Veröffentlicht 06.06.2023 19:15:12
- Zuletzt bearbeitet 21.11.2024 08:06:20
Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to upload attachments to test plans, test cases, etc. Earlier versions of Kiwi TCMS had introduced upload validators in order to prevent ...
CVE-2023-32686
- EPSS 0.43%
- Veröffentlicht 27.05.2023 04:15:25
- Zuletzt bearbeitet 21.11.2024 08:03:51
Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to upload attachments to test plans, test cases, etc. Earlier versions of Kiwi TCMS had introduced upload validators in order to prevent ...
CVE-2023-30628
- EPSS 3.6%
- Veröffentlicht 24.04.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 08:00:32
Kiwi TCMS is an open source test management system. In kiwitcms/Kiwi v12.2 and prior and kiwitcms/enterprise v12.2 and prior, the `changelog.yml` workflow is vulnerable to command injection attacks because of using an untrusted `github.head_ref` fiel...
CVE-2023-30544
- EPSS 0.42%
- Veröffentlicht 24.04.2023 17:15:10
- Zuletzt bearbeitet 04.02.2025 19:15:29
Kiwi TCMS is an open source test management system. In versions of Kiwi TCMS prior to 12.2, users were able to update their email addresses via the `My profile` admin page. This page allowed them to change the email address registered with their acco...
- EPSS 1.02%
- Veröffentlicht 24.04.2023 17:15:10
- Zuletzt bearbeitet 11.04.2025 14:50:37
Kiwi TCMS, an open source test management system, allows users to upload attachments to test plans, test cases, etc. In versions of Kiwi TCMS prior to 12.2, there is no control over what kinds of files can be uploaded. Thus, a malicious actor may upl...
CVE-2023-27489
- EPSS 0.49%
- Veröffentlicht 29.03.2023 19:15:22
- Zuletzt bearbeitet 21.11.2024 07:53:00
Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS accepts SVG files uploaded by users which could potentially contain JavaScript code. If SVG images are viewed directly, i.e. not rendered in an HTML p...