CVE-2023-25171 affects Kiwi TCMS versions prior to 12.0, stemming from a lack of rate limiting on the password reset page. This medium-severity vulnerability (CVSS 5.9) allows unauthenticated attackers to initiate denial-of-service attacks by flooding the system with password reset requests, potentially exhausting SMTP resources and sending numerous emails to known user addresses. While no active exploitation, public exploit code, or significant community discussion has been observed, users are advised to upgrade to version 12.0 or implement rate-limiting proxies or email server configurations as workarounds.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.0CPE matchmatch criteria | cpe:2.3:a:kiwitcms:kiwi_tcms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.