VDB
Sign up
MEDIUM4.6

GHSA-2xwq-h7r9-6w27

Cross-site Scripting in kimai2

Quick fix

GHSA-2xwq-h7r9-6w27 — kevinpapst/kimai2: upgrade to the fixed version with the command below.

composer require kevinpapst/kimai2:^1.16

Details

Cross site request forgery vulnerability is present in delete functionality of doctor feature. This vulnerability is capable of deleting system logs

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/kevinpapst/kimai2
Introduced in: 0Fixed in: 1.16
Fixcomposer require kevinpapst/kimai2:^1.16

References