MEDIUM4.3
GHSA-427q-jp8v-ww95
Cross-site Scripting in kimai2
Quick fix
GHSA-427q-jp8v-ww95 — kevinpapst/kimai2: upgrade to the fixed version with the command below.
composer require kevinpapst/kimai2:^1.16.2Details
CSRF related to duplicate action. (the duplication occurs first before redirecting to edit form). This vulnerability is capable of tricking admin users to duplicate teams.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/kevinpapst/kimai2
Introduced in:
0Fixed in: 1.16.2Fix
composer require kevinpapst/kimai2:^1.16.2