ZeroHour

CVE-2021-43515

CVSS 3.1
7.8 high
EPSS
1%p61
Published
()
Modified
Description

CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By filling the Description field with malicious payload, it will be mistreated while exporting to a CSV file.

Vendors
kimai
Products
kimai
Weakness
CWE-1236
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.