Miggo Logo

CVE-2023-27489: Kiwi TCMS Stored Cross-site Scripting via SVG file

7.6

CVSS Score
3.1

Basic Information

EPSS Score
0.61577%
Published
3/30/2023
Updated
4/6/2023
KEV Status
No
Technology
TechnologyPython

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
Package NameEcosystemVulnerable VersionsFirst Patched Version
kiwitcmspip< 12.112.1

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

### Imp**t Kiwi T*MS ****pts SV* *il*s uplo**** *y us*rs w*i** *oul* pot*nti*lly *ont*in J*v*S*ript *o**. I* SV* im***s *r* vi*w** *ir**tly, i.*. not r*n**r** in *n *TML p***, t*is J*v*S*ript *o** *oul* *x**ut*. ### P*t***s T*is vuln*r**ility **s *

Reasoning

No *n*lysis *v*il**l*