PT-2023-21164 · Kiwi Tcms · Kiwi Tcms

·

CVE-2023-27489

·

Published

2023-03-29

·

Updated

2026-07-07

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Kiwi TCMS versions prior to 12.1
Description The issue arises from Kiwi TCMS accepting SVG files uploaded by users, which could contain JavaScript code. If these SVG images are viewed directly, the JavaScript code could execute. This has been fixed by configuring Kiwi TCMS to serve with the Content-Security-Policy HTTP header, which blocks inline JavaScript in all modern browsers.
Recommendations For versions prior to 12.1, upgrade to version 12.1 to resolve the issue. As a temporary workaround for users unable to upgrade, manually set the Content-Security-Policy HTTP header to block inline JavaScript.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-27489
GHSA-2WCR-87WF-CF9J
PYSEC-2026-1496

Affected Products

Kiwi Tcms