Kimai 2- persistent cross-site scripting (XSS)
Vulnerability Description
Kimai 2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into timesheet descriptions. Attackers can insert SVG-based XSS payloads in the description field to execute arbitrary JavaScript when the page is loaded and viewed by other users.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-25317
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- osamaalaa
References
More from kevinpapst
View All →Affected Vendor
kevinpapst
View all reports →