GHSA-7x6q-3v3m-cwjg

    Dashboard / Vulnerabilities / GHSA-7x6q-3v3m-cwjg

    GHSA-7x6q-3v3m-cwjg

    Published: 24 Apr 2023Last Modified: 10 Sept 2026

    Summary: kiwi TCMS has possibility for user to update email address to unverified one

    Details: ### Impact In previous versions of Kiwi TCMS users were able to update their email addresses via the "My profile" admin page. This page allowed them to change the email address registered with their account without the ownership verification performed during account registration. ### Patches With Kiwi TCMS v12.2 or later it is not possible to edit the email field associated with a user account! ### Workarounds No workaround exists. ### References Disclosed by [@novemberdad](https://huntr.dev/bounties/1714df73-e639-4d64-ab25-ced82dad9f85/).

    Affected packages

    Package

    Name: kiwitcms

    Purl: pkg:pypi/kiwitcms

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -12.2

    Affected versions

    10.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-7x6q-3v3m-cwjg | CVE-DB