VYPR

Kimai2

by Kevinpapst

Source repositories

CVEs (1)

  • CVE-2023-53957Dec 19, 2025
    risk 0.00cvss epss 0.00

    Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP script that captures and writes session cookie information to a file, enabling potential session hijacking.