Beveiligingsadvies

CVE-2019-25317

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-02-11 14:56:54
Laatst bijgewerkt 2026-06-23 16:13:01
Toegewezen door VulnCheck
CVSS-score 6.4
Status PUBLISHED

Beschrijving

Kimai 2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into timesheet descriptions. Attackers can insert SVG-based XSS payloads in the description field to execute arbitrary JavaScript when the page is loaded and viewed by other users.