Medium severity6.1NVD Advisory· Published Dec 1, 2021· Updated Jun 17, 2026
CVE-2021-3983
CVE-2021-3983
Description
kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
kevinpapst/kimai2Packagist | < 1.16.3 | 1.16.3 |
Affected products
2- kevinpapst/kevinpapst/kimai2v5Range: unspecified
Patches
Vulnerability mechanics
References
5- github.com/kevinpapst/kimai2/commit/89bfa82c61da0d3639e4038e689e25467baac8a0nvdPatchThird Party AdvisoryWEB
- huntr.dev/bounties/c96f3480-dccf-4cc2-99a4-d2b3a7462413nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-67c7-5v9j-227rghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-3983ghsaADVISORY
- github.com/kevinpapst/kimai2/releases/tag/1.16.3ghsaWEB
News mentions
0No linked articles in our index yet.