MEDIUM6.1
GHSA-7v44-75jf-22gj
Kimai v2 is vulnerable to Cross-Site Scripting (XSS)
Quick fix
GHSA-7v44-75jf-22gj — kevinpapst/kimai2: upgrade to the fixed version with the command below.
composer require kevinpapst/kimai2:^1.1Details
Kimai v2 before 1.1 has XSS via a timesheet description.
Are you affected?
Enter the version of the package you're using.