CVE-2021-3983: Cross-site Scripting (XSS) - Stored in kevinpapst/kimai2
Published Dec 1, 2021
·Updated
kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Affected Software
1 affected component
Kimai2 Project Kimai2<1.16.3
Remediation
Event History
Dec 1, 2021
CVE Published
via MITRE·11:15 AM
Data Sourced
via MITRE·11:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-3983?
CVE-2021-3983 is classified as a medium severity vulnerability due to its potential exploitation via cross-site scripting.
2
How do I fix CVE-2021-3983?
To fix CVE-2021-3983, upgrade Kimai2 to version 1.16.3 or later.
3
What type of vulnerability is CVE-2021-3983?
CVE-2021-3983 is a Cross-site Scripting (XSS) vulnerability resulting from improper input neutralization.
4
What are the potential impacts of exploiting CVE-2021-3983?
Exploiting CVE-2021-3983 can allow an attacker to execute arbitrary JavaScript in the context of a user's session.
5
Which versions of Kimai are affected by CVE-2021-3983?
Kimai versions prior to 1.16.3 are affected by CVE-2021-3983.