CVE-2021-43515: High severity kimai vulnerability
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By filling the Description field with malicious payload, it will be mistreated while exporting to a CSV file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CSV Injection (aka Excel Macro Injection or Formula Injection)?
CSV Injection (aka Excel Macro Injection or Formula Injection) is a vulnerability where an attacker can inject malicious formulas or macros into a CSV file, which can lead to the execution of arbitrary code when the file is opened in a vulnerable application like Microsoft Excel.
How does the CSV Injection vulnerability affect Kimai (version 1.14.1)?
The CSV Injection vulnerability in Kimai version 1.14.1 allows an attacker to inject malicious payload into the Description field when creating a new timesheet, which can be misinterpreted when the data is exported to a CSV file.
What is the severity of CVE-2021-43515?
CVE-2021-43515 has a severity score of 7.8 (high).
How can I fix the CSV Injection vulnerability in Kimai (version 1.14.1)?
To fix the CSV Injection vulnerability in Kimai version 1.14.1, you should update to a patched version of Kimai that addresses the issue, such as version X.X.X or later.
Is there any additional information about CVE-2021-43515?
Yes, you can find more information about CVE-2021-43515 and the fix in the official GitHub repository of Kimai.