CVE-2021-3976

MEDIUM4.3EPSS 0.10%

Cross-site Scripting in kimai2

發布日:2021/11/23修改日:2023/11/8

描述

CSRF related to duplicate action. (the duplication occurs first before redirecting to edit form). This vulnerability is capable of tricking admin users to duplicate teams.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM4.3CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

參考連結(3)