High severityNVD Advisory· Published Oct 31, 2023· Updated Aug 2, 2024
Kimai (Authenticated) SSTI to RCE by Uploading a Malicious Twig File
CVE-2023-46245
Description
Kimai is a web-based multi-user time-tracking application. Versions prior to 2.1.0 are vulnerable to a Server-Side Template Injection (SSTI) which can be escalated to Remote Code Execution (RCE). The vulnerability arises when a malicious user uploads a specially crafted Twig file, exploiting the software's PDF and HTML rendering functionalities. Version 2.1.0 enables security measures for custom Twig templates.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
kimai/kimaiPackagist | < 2.1.0 | 2.1.0 |
Affected products
2Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-fjhg-96cp-6fcwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-46245ghsaADVISORY
- github.com/kimai/kimai/commit/38e37f1c2e91e1acb221ec5c13f11b735bd50ae4ghsax_refsource_MISCWEB
- github.com/kimai/kimai/security/advisories/GHSA-fjhg-96cp-6fcwghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.