Impact
Prior to version 16.1, Kiwi TCMS accepted arbitrary input in the TestCase.extra_link and TestPlan.extra_link fields, rendering stored values verbatim when the link is displayed. While the CVE description does not explicitly state the authentication requirement, it can be inferred that a user who can write these fields—typically an authenticated user—could inject a javascript: URI that will execute in the victim’s browser when the link is clicked, enabling session hijacking, privilege escalation, or defacement. Official builds send a Content‑Security‑Policy header that blocks inline JavaScript, which mitigates exploitation in default deployments, but deployments that disable or weaken this header remain vulnerable.
Affected Systems
All Kiwi TCMS installations using versions earlier than 16.1 are affected. The vulnerability applies to the default open‑source distribution as well as to modified deployments. Official Docker images and the unmodified middleware ship a Content‑Security‑Policy header that blocks inline JavaScript, which reduces the likelihood of successful exploitation in typical installations. Custom deployments that relax CSP configuration or otherwise weaken security controls remain vulnerable.
Risk and Exploitability
The EPSS score of less than 1 % indicates that exploitation is considered unlikely by current threat intelligence. This issue is not listed in the CISA KEV catalog. Exploitation requires an authenticated user who can create or edit a TestCase or TestPlan record; the attacker then injects a javascript: URI into the extra_link field. Successful exploitation depends on the victim viewing the affected link in a context where the CSP does not block inline scripts. Because the default configuration blocks inline scripts, the risk is mitigated on standard deployments, but customized configurations that remove or weaken the CSP header render the vulnerability exploitable. The likely attack vector is inferred to be an authenticated user who injects a malicious javascript: URI into these fields, as the description indicates that the application renders stored values verbatim.
OpenCVE Enrichment
Github GHSA