High severity7.8NVD Advisory· Published Apr 8, 2022· Updated Jun 17, 2026
CVE-2021-43515
CVE-2021-43515
Description
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By filling the Description field with malicious payload, it will be mistreated while exporting to a CSV file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
kevinpapst/kimai2Packagist | < 1.14.1 | 1.14.1 |
Affected products
2Patches
Vulnerability mechanics
References
4- github.com/kevinpapst/kimai2/commit/dad1b8b772947f1596175add1b4f33b791705507nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-64fq-9c6w-rq44ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-43515ghsaADVISORY
- github.com/kevinpapst/kimai2/pull/2532ghsaWEB
News mentions
0No linked articles in our index yet.