CVE-2023-25156
- EPSS 0.9%
- Veröffentlicht 15.02.2023 15:15:11
- Zuletzt bearbeitet 21.11.2024 07:49:13
Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt brute-force attacks against the login page. Users should upgrade to v12.0 or later to receive a patch. As a worka...
CVE-2023-25171
- EPSS 0.91%
- Veröffentlicht 15.02.2023 15:15:11
- Zuletzt bearbeitet 21.11.2024 07:49:14
Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt denial-of-service attacks against the Password reset page. An attacker could potentially send a large number of e...
CVE-2023-22451
- EPSS 0.68%
- Veröffentlicht 02.01.2023 16:15:11
- Zuletzt bearbeitet 21.11.2024 07:44:49
Kiwi TCMS is an open source test management system. In version 11.6 and prior, when users register new accounts and/or change passwords, there is no validation in place which would prevent them from picking an easy to guess password. This issue is re...
CVE-2022-4105
- EPSS 0.45%
- Veröffentlicht 21.11.2022 20:15:11
- Zuletzt bearbeitet 21.11.2024 07:34:35
A stored XSS in a kiwi Test Plan can run malicious javascript which could be chained with an HTML injection to perform a UI redressing attack (clickjacking) and an HTML injection which disables the use of the history page.