CVE-2023-53957: Kimai 1.30.10 SameSite Cookie Vulnerability Session Hijacking
Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP script that captures and writes session cookie information to a file, enabling potential session hijacking.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-53957?
CVE-2023-53957 is considered a high-severity vulnerability due to its potential to allow attackers to steal user session cookies.
How do I fix CVE-2023-53957?
To fix CVE-2023-53957, ensure that your Kimai installation is updated to version 1.30.11 or later, which addresses the SameSite cookie vulnerability.
What is the impact of CVE-2023-53957?
The impact of CVE-2023-53957 is that it enables session hijacking, allowing attackers to impersonate users by stealing their session cookies.
Which versions of Kimai are affected by CVE-2023-53957?
CVE-2023-53957 affects Kimai versions prior to 1.30.11, specifically version 1.30.10.
Who can exploit CVE-2023-53957?
Remote attackers can exploit CVE-2023-53957 by tricking users into executing a crafted PHP script, thereby capturing session cookie information.