CVE-2020-19825: XSS
Published Feb 15, 2023
·Updated
Cross Site Scripting (XSS) vulnerability in kevinpapst kimai2 1.30.0 in /src/Twig/Runtime/MarkdownExtension.php, allows attackers to gain escalated privileges.
Affected Software
1 affected component
Kimai kimai=1.30.0
Remediation
Patch Available
Event History
Feb 15, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-19825?
The severity of CVE-2020-19825 is critical with a CVSS score of 9.6.
2
How can an attacker exploit CVE-2020-19825?
An attacker can exploit CVE-2020-19825 by injecting malicious code into the affected application, allowing them to gain escalated privileges.
3
Which version of Kevinpapst Kimai2 is affected by CVE-2020-19825?
Kevinpapst Kimai2 version 1.30.0 is affected by CVE-2020-19825.
4
Is there a fix available for CVE-2020-19825?
Yes, a fix is available for CVE-2020-19825. It is recommended to update to a patched version of Kimai2.
5
Where can I find more information about CVE-2020-19825?
More information about CVE-2020-19825 can be found on the GitHub page of Kevinpapst Kimai2.