CVE-2021-3976

MEDIUM4.3EPSS 0.10%

Cross-site Scripting in kimai2

Published: 11/23/2021Modified: 11/8/2023
Also known as:GHSA-427q-jp8v-ww95

Description

CSRF related to duplicate action. (the duplication occurs first before redirecting to edit form). This vulnerability is capable of tricking admin users to duplicate teams.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.3CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

References (3)