PT-2023-23961 · Kiwi Tcms · Kiwi Tcms

·

CVE-2023-32686

·

Publicado

2023-05-22

·

Atualizado

2026-07-07

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Kiwi TCMS versions prior to 12.3
Description The issue arises from insufficient upload validation checks in Kiwi TCMS, allowing an attacker to upload potentially dangerous files. These files can be combined to circumvent the existing Content-Security-Policy, enabling the execution of arbitrary JavaScript in the browser.
Recommendations For versions prior to 12.3, update to version 12.3 to resolve the issue. As a temporary workaround, consider implementing a custom Django middleware, such as ExtraHeadersMiddleware, to force the Content-Type: text/plain header when serving uploaded files. Alternatively, force the Content-Type header via Nginx overrides, specifically for the /uploads/ location.

Exploit

Correção

Unrestricted File Upload

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-32686
GHSA-X7C2-7WVG-JPX7
PYSEC-2026-1500

Produtos afetados

Kiwi Tcms