Vulnerability Description
Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP script that captures and writes session cookie information to a file, enabling potential session hijacking.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kimai | Kimai | 1.30.10 |
Related Weaknesses (CWE)
References
- https://github.com/kimai/kimai/releases/tag/1.30.10ProductRelease Notes
- https://www.exploit-db.com/exploits/51278ExploitThird Party AdvisoryVDB Entry
- https://www.vulncheck.com/advisories/kimai-samesite-cookie-vulnerability-sessionThird Party Advisory
FAQ
What is CVE-2023-53957?
CVE-2023-53957 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP scri...
How severe is CVE-2023-53957?
CVE-2023-53957 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-53957?
Check the references section above for vendor advisories and patch information. Affected products include: Kimai Kimai.