Impact
Kiwi TCMS exposes an /init-db/ web page that, after the first database setup, remains reachable without authentication. The page forwards every request to the Django migrate command, which is re‑entrant; therefore repeated accesses merely report that no migrations are pending and neither alter the database state nor leak sensitive data. Consequently, the vulnerability is a missing authorization flaw (CWE‑862) that does not allow data loss, privilege escalation, or service disruption, although an attacker can discover that the endpoint exists.
Affected Systems
All installations of Kiwi TCMS older than version 16.0 are affected. The vulnerability was fixed in release 16.0 of the open‑source Kiwi TCMS management suite.
Risk and Exploitability
The EPSS probability is reported as less than 1 %, indicating a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need only unauthenticated reach to the web server to access the /init-db/ page; no additional credentials, network privileges or application state changes are required. Because the endpoint merely reports that no migrations remain and does not modify data, the overall risk and impact for confidentiality, integrity, and availability are negligible, but the exposed endpoint remains an unnecessary attack surface.
OpenCVE Enrichment
Github GHSA