CVE-2021-3963: Cross-Site Request Forgery (CSRF) in kevinpapst/kimai2
Published Nov 19, 2021
·Updated
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
Affected Software
1 affected component
Kimai Kimai 2<1.16.2
Remediation
Event History
Nov 19, 2021
CVE Published
via MITRE·11:50 AM
Data Sourced
via MITRE·11:50 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-3963?
CVE-2021-3963 refers to a vulnerability in kimai2 that allows for Cross-Site Request Forgery (CSRF) attacks.
2
How severe is CVE-2021-3963?
CVE-2021-3963 has a severity rating of medium with a score of 4.3.
3
What version of kimai2 is affected by CVE-2021-3963?
kimai2 version 1.16.2 and earlier are affected by CVE-2021-3963.
4
How can I fix CVE-2021-3963?
To fix CVE-2021-3963, update to a version of kimai2 that is not vulnerable.
5
Where can I find more information about CVE-2021-3963?
You can find more information about CVE-2021-3963 on the GitHub commit and huntr.dev bounty page.