MEDIUM4.6
GHSA-2xwq-h7r9-6w27
Cross-site Scripting in kimai2
Quick fix
GHSA-2xwq-h7r9-6w27 — kevinpapst/kimai2: upgrade to the fixed version with the command below.
composer require kevinpapst/kimai2:^1.16Details
Cross site request forgery vulnerability is present in delete functionality of doctor feature. This vulnerability is capable of deleting system logs
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/kevinpapst/kimai2
Introduced in:
0Fixed in: 1.16Fix
composer require kevinpapst/kimai2:^1.16