Denial of service vulnerability on Password reset page
GHSA-7j9h-3jxf-3vrf · CVE-2023-25171
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
Previous versions of Kiwi TCMS do not impose rate limits which makes it easier to attempt denial-of-service attacks against the Password reset page. An attacker could potentially send a large number of emails if they know the email addresses of users in Kiwi TCMS. Additionally that may strain SMTP resources.
Patches
Users should upgrade to v12.0 or later.
Workarounds
Users may install and configure a rate-limiting proxy in front of Kiwi TCMS such as Nginx and/or configure rate limits on their email server when possible.
References
References
- WEB https://github.com/kiwitcms/Kiwi/security/advisories/GHSA-7j9h-3jxf-3vrf
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2023-25171
- WEB https://github.com/kiwitcms/Kiwi/commit/761305d04f5910ba14cc04d1255a8f1afdbb87f3
- PACKAGE https://github.com/kiwitcms/Kiwi
- WEB https://huntr.dev/bounties/3b712cb6-3fa3-4f71-8562-7a7016c6262e
- WEB https://kiwitcms.org/blog/kiwi-tcms-team/2023/02/15/kiwi-tcms-120
Ready to move
Start Securing
Free, no credit card | First findings in minutes