CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By filling the Description field with malicious payload, it will be mistreated while exporting to a CSV file.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HKimai
APPKimai< 1.14.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2020-19825CRITICAL9.6PL ✓same product
XSS w Kimai 2 umożliwiający eskalację uprawnień
CVE-2023-53957HIGH8.5same product
Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies thr...
CVE-2023-46245HIGH7.2same product
Kimai is a web-based multi-user time-tracking application. Versions prior to 2.1.0 are vulnerable to a Server-...
CVE-2026-42267MEDIUM5.4same product
Kimai to otwarte oprogramowanie do śledzenia czasu pracy. W wersjach od 2.27.0 do przed 2.54.0, każdy użytkown...
CVE-2026-44298MEDIUM4.1same product
Kimai jest open-source'ową aplikacją do śledzenia czasu pracy. W wersjach od 2.32.0 do przed wersją 2.56.0, uż...