CVE-2023-25156 is a critical vulnerability affecting Kiwi TCMS versions prior to 12.0, stemming from a lack of rate limiting on the login page. This flaw significantly increases the risk of brute-force attacks. With a CVSS score of 9.8 (CRITICAL), it is easily exploitable over the network with low complexity, potentially leading to full compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation, public exploit code, or significant community discussion, users are strongly advised to upgrade to version 12.0 or later, or implement a rate-limiting proxy as a workaround.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.0CPE matchmatch criteria | cpe:2.3:a:kiwitcms:kiwi_tcms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.