Critical severity9.8OSV Advisory· Published Dec 19, 2025· Updated Jun 17, 2026
CVE-2023-53957
CVE-2023-53957
Description
Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP script that captures and writes session cookie information to a file, enabling potential session hijacking.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
kimai/kimaiPackagist | <= 1.30.10 | — |
Affected products
3- Range: 0.1, 0.2, 0.3, …
Patches
Vulnerability mechanics
References
5- www.exploit-db.com/exploits/51278nvdExploitThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-cv8h-r7r5-vwj9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-53957ghsaADVISORY
- www.vulncheck.com/advisories/kimai-samesite-cookie-vulnerability-session-hijackingnvdThird Party AdvisoryWEB
- github.com/kimai/kimai/releases/tag/1.30.10nvdProductRelease Notes
News mentions
0No linked articles in our index yet.