CVE-2021-3957

MEDIUM4.6EPSS 0.09%

Cross-site Scripting in kimai2

Published: 11/23/2021Modified: 11/8/2023
Also known as:GHSA-2xwq-h7r9-6w27

Description

Cross site request forgery vulnerability is present in delete functionality of doctor feature. This vulnerability is capable of deleting system logs

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.6CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L

References (3)