icon

We found results for “

WS-2023-0104

Good to know:

icon

Date: March 26, 2023

A Stored HTML injection to XSS vulnerability was found in GitHub repository kimai/kimai prior to 2.0.13.

Language: PHP

Severity Score

Severity Score

Weakness Type (CWE)

Improper Control of Generation of Code ('Code Injection')

CWE-94

Top Fix

icon

Upgrade Version

Upgrade to version kimai/kimai - 1.0;kimai/kimai - dev-release-2.0-beta-3;kimai/kimai - dev-2fa-saml;kimai/kimai - dev-release-2-0-2;kimai/kimai - dev-release-2.0.12;kimai/kimai - dev-release-2.0.4;kimai/kimai - dev-release-1.30.3;kimai/kimai - dev-release-2.0.11;kimai/kimai - 1.1.0;kimai/kimai - dev-kevinpapst-patch-1;kimai/kimai - dev-fixes-1.12;kimai/kimai - dev-release-1.30.1;kimai/kimai - dev-release-2.0.5;kimai/kimai - v1.3.2;kimai/kimai - 1.3;kimai/kimai - dev-release-2.0-beta

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): HIGH
User Interaction (UI): REQUIRED
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): LOW
Availability (A): HIGH

Do you need more information?

Contact Us