CVE-2021-3985: Cross-site Scripting (XSS) - Stored in kevinpapst/kimai2
Published Dec 1, 2021
·Updated
kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Affected Software
1 affected component
Kimai kimai2<1.16.3
Remediation
Event History
Dec 1, 2021
CVE Published
via MITRE·11:05 AM
Data Sourced
via MITRE·11:05 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-3985?
CVE-2021-3985 is a vulnerability in kimai2 that allows an attacker to execute malicious scripts in a victim's browser.
2
How severe is CVE-2021-3985?
CVE-2021-3985 is considered a critical vulnerability with a severity value of 9.
3
What is the affected version of kimai2?
kimai2 version up to and excluding 1.16.3 is affected by CVE-2021-3985.
4
How can I fix CVE-2021-3985?
To fix CVE-2021-3985, you should update kimai2 to version 1.16.3 or higher.
5
Where can I find more information about CVE-2021-3985?
You can find more information about CVE-2021-3985 at the following references: [GitHub Commit](https://github.com/kevinpapst/kimai2/commit/76e09447c85e762882126b49626a4fe4d93fe8b5) and [Huntr Bounty](https://huntr.dev/bounties/89d6c3de-efbd-4354-8cc8-46e999e4c5a4).