vendor:
Kimai 2
by:
osamaalaa
4.3
CVSS
MEDIUM
Persistent Cross-Site Scripting (XSS)
79
CWE
Product Name: Kimai 2
Affected Version From: 2
Affected Version To: 2
Patch Exists: YES
Related CWE: N/A
CPE: a:kevinpapst:kimai2
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2019
Kimai 2- persistent cross-site scripting (XSS)
Kimai 2 is vulnerable to persistent cross-site scripting (XSS). A normal user can add a malicious payload in the description field of the timesheet creation page. When the changes are saved and the page is refreshed, an alert pop up is triggered.
Mitigation:
Input validation should be used to prevent malicious payloads from being added to the description field.