PT-2026-7611 · Kimai2 · Kimai2

Osamaalaa

·

Published

2026-02-11

·

Updated

2026-02-19

·

CVE-2019-25317

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kimai 2 (affected versions not specified)
Description The software contains a persistent cross-site scripting issue that enables attackers to inject malicious scripts into timesheet descriptions. Attackers can insert SVG-based XSS payloads into the description field, leading to the execution of arbitrary JavaScript when the page is loaded and viewed by other users.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2019-25317
GHSA-9278-6HCJ-2P4J

Affected Products

Kimai2