Lucene search

K

Kimai Security Vulnerabilities

cve
cve

CVE-2024-29200

Kimai is a web-based multi-user time-tracking application. The permission view_other_timesheet performs differently for the Kimai UI and the API, thus returning unexpected data through the API. When setting the view_other_timesheet permission to true, on the frontend, users can only see timesheet.....

6.8CVSS

6.4AI Score

0.0004EPSS

2024-03-28 02:15 PM
28
cve
cve

CVE-2023-46245

Kimai is a web-based multi-user time-tracking application. Versions prior to 2.1.0 are vulnerable to a Server-Side Template Injection (SSTI) which can be escalated to Remote Code Execution (RCE). The vulnerability arises when a malicious user uploads a specially crafted Twig file, exploiting the...

7.2CVSS

7.3AI Score

0.001EPSS

2023-10-31 04:15 PM
48
cve
cve

CVE-2020-19825

Cross Site Scripting (XSS) vulnerability in kevinpapst kimai2 1.30.0 in /src/Twig/Runtime/MarkdownExtension.php, allows attackers to gain escalated...

9.6CVSS

8.5AI Score

0.002EPSS

2023-02-15 10:15 PM
30
cve
cve

CVE-2021-43515

CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By filling the Description field with malicious payload, it will be mistreated while exporting to a CSV...

7.8CVSS

7.6AI Score

0.001EPSS

2022-04-08 05:15 PM
57
cve
cve

CVE-2021-4033

kimai2 is vulnerable to Cross-Site Request Forgery...

6.5CVSS

6.4AI Score

0.001EPSS

2021-12-09 08:15 PM
32
cve
cve

CVE-2021-3985

kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site...

9CVSS

8.9AI Score

0.001EPSS

2021-12-01 11:15 AM
30
cve
cve

CVE-2021-3963

kimai2 is vulnerable to Cross-Site Request Forgery...

4.3CVSS

4.5AI Score

0.001EPSS

2021-11-19 12:15 PM
33
cve
cve

CVE-2021-3957

kimai2 is vulnerable to Cross-Site Request Forgery...

4.3CVSS

4.5AI Score

0.001EPSS

2021-11-19 12:15 PM
30
cve
cve

CVE-2021-3976

kimai2 is vulnerable to Cross-Site Request Forgery...

6.5CVSS

6.4AI Score

0.001EPSS

2021-11-19 11:15 AM
36
cve
cve

CVE-2019-15481

Kimai v2 before 1.1 has XSS via a timesheet...

6.1CVSS

5.9AI Score

0.001EPSS

2019-08-23 01:15 PM
42