CVE-2019-15481: XSS
Published Aug 23, 2019
·Updated
Kimai v2 before 1.1 has XSS via a timesheet description.
Affected Software
2 affected componentsFixes available
composer/kevinpapst/kimai2<1.1
1.1
Kimai Kimai 2<1.1
Remediation
Patch Available
Event History
Aug 23, 2019
CVE Published
via MITRE·12:25 PM
Data Sourced
via MITRE·12:25 PM
Description
May 24, 2022
Advisory Published
04:54 PM
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2019-15481.
2
What is the severity of CVE-2019-15481?
The severity of CVE-2019-15481 is medium with a CVSS score of 6.1.
3
How can an attacker exploit CVE-2019-15481?
An attacker can exploit CVE-2019-15481 through a timesheet description that contains malicious code, leading to XSS (Cross-Site Scripting) attacks.
4
Which versions of Kimai 2 are affected by CVE-2019-15481?
Kimai v2 versions up to and excluding 1.1 are affected by CVE-2019-15481.
5
How can I mitigate CVE-2019-15481?
To mitigate CVE-2019-15481, upgrade to version 1.1 or later of Kimai v2.