Kiwi TCMS is an open source test management system. In versions of Kiwi TCMS prior to 12.2, users were able to update their email addresses via the `My profile` admin page. This page allowed them to change the email address registered with their account without the ownership verification performed during account registration. Operators of Kiwi TCMS should upgrade to v12.2 or later to receive a patch. No known workarounds exist.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1233 | Kiwi TCMS is an open source test management system. In versions of Kiwi TCMS prior to 12.2, users were able to update their email addresses via the `My profile` admin page. This page allowed them to change the email address registered with their account without the ownership verification performed during account registration. Operators of Kiwi TCMS should upgrade to v12.2 or later to receive a patch. No known workarounds exist. |
Github GHSA |
GHSA-7x6q-3v3m-cwjg | kiwi TCMS has possibility for user to update email address to unverified one |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 04 Feb 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-04T18:46:23.973Z
Reserved: 2023-04-12T15:19:33.767Z
Link: CVE-2023-30544
Updated: 2024-08-02T14:28:51.914Z
Status : Modified
Published: 2023-04-24T17:15:10.777
Modified: 2025-02-04T19:15:29.200
Link: CVE-2023-30544
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA