kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://huntr.dev/bounties/3abf308b-7dbd-4864-b1a9-5c45b876def8 | patch exploit third party advisory issue tracking |
https://github.com/kevinpapst/kimai2/commit/95796ab2560ad93f44068a88f0fad758c2053514 | third party advisory patch |