HIGH🇬🇧 English

CVE-2023-46245

CVSS 7.2v3.1pub. 2023-10-31upd. 2024-11-21

Kimai is a web-based multi-user time-tracking application. Versions prior to 2.1.0 are vulnerable to a Server-Side Template Injection (SSTI) which can be escalated to Remote Code Execution (RCE). The vulnerability arises when a malicious user uploads a specially crafted Twig file, exploiting the software's PDF and HTML rendering functionalities. Version 2.1.0 enables security measures for custom Twig templates.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Kimai

    APP
    Kimai
    ≤ 2.10
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
RCE
CWE
Referencje

Powiązane podatności

CVE-2020-19825CRITICAL9.6PL ✓ten sam produkt

XSS w Kimai 2 umożliwiający eskalację uprawnień

CVE-2023-53957HIGH8.5ten sam produkt

Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies thr...

CVE-2021-43515HIGH7.8ten sam produkt

CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By f...

CVE-2026-42267MEDIUM5.4ten sam produkt

Kimai to otwarte oprogramowanie do śledzenia czasu pracy. W wersjach od 2.27.0 do przed 2.54.0, każdy użytkown...

CVE-2026-44298MEDIUM4.1ten sam produkt

Kimai jest open-source'ową aplikacją do śledzenia czasu pracy. W wersjach od 2.32.0 do przed wersją 2.56.0, uż...