Vulnerabilities
Vulnerable Software
Kimai:  >> Kimai  >> 1.30.0  Security Vulnerabilities
Kimai is a web-based multi-user time-tracking application. Versions prior to 2.1.0 are vulnerable to a Server-Side Template Injection (SSTI) which can be escalated to Remote Code Execution (RCE). The vulnerability arises when a malicious user uploads a specially crafted Twig file, exploiting the software's PDF and HTML rendering functionalities. Version 2.1.0 enables security measures for custom Twig templates.
CVSS Score
7.2
EPSS Score
0.023
Published
2023-10-31
Cross Site Scripting (XSS) vulnerability in kevinpapst kimai2 1.30.0 in /src/Twig/Runtime/MarkdownExtension.php, allows attackers to gain escalated privileges.
CVSS Score
9.6
EPSS Score
0.004
Published
2023-02-15


Contact Us

Shodan ® - All rights reserved