Логотип exploitDog
bind:CVE-2023-46245
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-46245

Количество 2

Количество 2

nvd логотип

CVE-2023-46245

больше 2 лет назад

Kimai is a web-based multi-user time-tracking application. Versions prior to 2.1.0 are vulnerable to a Server-Side Template Injection (SSTI) which can be escalated to Remote Code Execution (RCE). The vulnerability arises when a malicious user uploads a specially crafted Twig file, exploiting the software's PDF and HTML rendering functionalities. Version 2.1.0 enables security measures for custom Twig templates.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-fjhg-96cp-6fcw

больше 2 лет назад

Kimai (Authenticated) SSTI to RCE by Uploading a Malicious Twig File

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-46245

Kimai is a web-based multi-user time-tracking application. Versions prior to 2.1.0 are vulnerable to a Server-Side Template Injection (SSTI) which can be escalated to Remote Code Execution (RCE). The vulnerability arises when a malicious user uploads a specially crafted Twig file, exploiting the software's PDF and HTML rendering functionalities. Version 2.1.0 enables security measures for custom Twig templates.

CVSS3: 7.2
2%
Низкий
больше 2 лет назад
github логотип
GHSA-fjhg-96cp-6fcw

Kimai (Authenticated) SSTI to RCE by Uploading a Malicious Twig File

CVSS3: 7.2
2%
Низкий
больше 2 лет назад

Уязвимостей на страницу