CVE-2021-3957: Cross-Site Request Forgery (CSRF) in kevinpapst/kimai2
Published Nov 19, 2021
·Updated
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
Affected Software
1 affected component
Kimai Kimai 2<1.16.2
Remediation
Event History
Nov 19, 2021
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-3957?
CVE-2021-3957 is a vulnerability in kimai2 that allows for Cross-Site Request Forgery (CSRF) attacks.
2
What is the severity of CVE-2021-3957?
The severity of CVE-2021-3957 is medium, with a CVSS score of 4.3.
3
Which version of kimai2 is affected by CVE-2021-3957?
kimai2 version 1.16.2 is affected by CVE-2021-3957.
4
How can I fix CVE-2021-3957?
To fix CVE-2021-3957, update kimai2 to a version that is secure and not affected by the vulnerability.
5
Where can I find more information about CVE-2021-3957?
More information about CVE-2021-3957 can be found at the following references: [Reference 1](https://github.com/kevinpapst/kimai2/commit/6b49535b523dcd36ec59462ee4e67e2b3a9151f3) and [Reference 2](https://huntr.dev/bounties/5fa3098a-ba02-45e0-af56-645e34dbc691).