Описание
Cross-site Scripting in kimai2
CSRF related to duplicate action. (the duplication occurs first before redirecting to edit form). This vulnerability is capable of tricking admin users to duplicate teams.
Пакеты
Наименование
kevinpapst/kimai2
composer
Затронутые версииВерсия исправления
< 1.16.2
1.16.2
Связанные уязвимости
CVSS3: 6.5
nvd
около 4 лет назад
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)