Impact
Kiwi TCMS is an open source test management system. Prior to version 16.1, the account confirmation endpoint accepted an unvalidated next parameter, allowing an unauthenticated attacker to create a URL on a trusted Kiwi TCMS hostname that redirects a victim to an arbitrary external domain. This is a CWE-601 open redirect vulnerability, where the unvalidated next parameter permits arbitrary redirection. The trusted origin can support credential‑harvesting pages, bypass email security filters and link‑reputation checks that allowlist the organization’s domain, or deliver malware through a convincing account-confirmation lure. This issue is fixed in version 16.1.
Affected Systems
The flaw exists in all Kiwi TCMS installations running versions before 16.1. The affected vendor is Kiwi. Updating to version 16.1 or later eliminates the issue.
Risk and Exploitability
The CVSS score of 6.1 indicates a medium severity impact. The EPSS score of < 1% indicates a very low exploitation probability. The vulnerability is not listed in CISA KEV. Attackers only need to craft a malicious link; no authentication is required. The likely attack vector is a crafted email or web link that directs a victim’s browser to the trusted Kiwi TCMS host, which then redirects them to an attacker-controlled site.
OpenCVE Enrichment
Github GHSA