MEDIUM6.5
GHSA-4jwx-78vx-gm6g
Cross-Site Request Forgery in kimai2
Quick fix
GHSA-4jwx-78vx-gm6g — kevinpapst/kimai2: upgrade to the fixed version with the command below.
composer require kevinpapst/kimai2:^1.16.7Details
CSRF in saving invoices / modifying status of invoices (pending and cancel only)
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/kevinpapst/kimai2
Introduced in:
0Fixed in: 1.16.7Fix
composer require kevinpapst/kimai2:^1.16.7