vendor:
Kimai
by:
Mohammed Aloraimi
N/A
CVSS
N/A
CSV Injection
CWE
Product Name: Kimai
Affected Version From: 1.14
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10
2021
Kimai 1.14 – CSV Injection
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By filling the Description field with malicious payload, it will be mistreated while exporting to a CSV file.
Mitigation:
Unknown