HIGH7.8
GHSA-64fq-9c6w-rq44
Improper Neutralization of Formula Elements in a CSV File in Kimai 2
Quick fix
GHSA-64fq-9c6w-rq44 — kevinpapst/kimai2: upgrade to the fixed version with the command below.
composer require kevinpapst/kimai2:^1.14.1Details
A CSV Injection vulnerablity exists in Kimai Kimai 2 prior to 1.14.1 via a description in a new timesheet.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/kevinpapst/kimai2
Introduced in:
0Fixed in: 1.14.1Fix
composer require kevinpapst/kimai2:^1.14.1References
- https://nvd.nist.gov/vuln/detail/CVE-2021-43515[ADVISORY]
- https://github.com/kevinpapst/kimai2/pull/2532[WEB]
- https://github.com/kevinpapst/kimai2/commit/dad1b8b772947f1596175add1b4f33b791705507#diff-6774f5865dbaf8bc6c55b75bd92e6f9950ebe7834aa2efd828a19fd637e667cf[WEB]
- https://github.com/kevinpapst/kimai2[PACKAGE]