Impact
Previous versions of Kiwi TCMS do not impose rate limits which makes it easier to attempt brute-force attacks against the login page.
Patches
Users should upgrade to v12.0 or later.
Workarounds
Users may install and configure a rate-limiting proxy in front of Kiwi TCMS. For example nginx.
References
Disclosed by spyata