Vulnerabilities
Vulnerable Software
Kimai:  >> Kimai  >> 1.16.9  Security Vulnerabilities
Kimai is a web-based multi-user time-tracking application. Versions prior to 2.1.0 are vulnerable to a Server-Side Template Injection (SSTI) which can be escalated to Remote Code Execution (RCE). The vulnerability arises when a malicious user uploads a specially crafted Twig file, exploiting the software's PDF and HTML rendering functionalities. Version 2.1.0 enables security measures for custom Twig templates.
CVSS Score
7.2
EPSS Score
0.023
Published
2023-10-31


Contact Us

Shodan ® - All rights reserved