Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-30613— Kiwi TCMS unrestricted file upload vulnerability

CVSS 8.1 · High EPSS 0.69% · P72
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-30613

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Kiwi TCMS unrestricted file upload vulnerability
Source: NVD (National Vulnerability Database)
Vulnerability Description
Kiwi TCMS, an open source test management system, allows users to upload attachments to test plans, test cases, etc. In versions of Kiwi TCMS prior to 12.2, there is no control over what kinds of files can be uploaded. Thus, a malicious actor may upload an `.exe` file or a file containing embedded JavaScript and trick others into clicking on these files, causing vulnerable browsers to execute malicious code on another computer. Kiwi TCMS v12.2 comes with functionality that allows administrators to configure additional upload validator functions which give them more control over what file types are accepted for upload. By default `.exe` are denied. Other files containing the `<script>` tag, regardless of their type are also denied b/c they are a path to XSS attacks. There are no known workarounds aside from upgrading.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
危险类型文件的不加限制上传
Source: NVD (National Vulnerability Database)
Vulnerability Title
Kiwi TCMS 代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Kiwi TCMS是Kiwi TCMS开源的一个用于手动和自动测试的领先开源测试管理系统。 Kiwi TCMS 12.2之前版本存在代码问题漏洞,该漏洞源于无法控制可以上传哪些类型的文件。攻击者利用该漏洞可以执行恶意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
kiwitcmsKiwi < 12.2 -

II. Public POCs for CVE-2023-30613

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-30613

登录查看更多情报信息。

Same Patch Batch · kiwitcms · 2023-04-24 · 3 CVEs total

CVE-2023-306288.8 HIGHKiwi TCMS has command injection vulnerability in changelog.yml CI workflow
CVE-2023-305443.9 LOWKiwi TCMS may allow user to update email address to unverified one

IV. Related Vulnerabilities

V. Comments for CVE-2023-30613

No comments yet


Leave a comment