Kevin Papst
10 exploits
Active since Nov 2021
Kimai <2.51.0 - Privilege Escalation
CVSS 6.5
Kimai2 < 1.16.2 - Cross-Site Request Forgery
CVSS 4.3
Kimai2 < 1.16.2 - Cross-Site Request Forgery
CVSS 4.3
Kimai2 < 1.16.2 - Cross-Site Request Forgery
CVSS 6.5
kimai2 < 1.16.3 - Stored Cross-Site Scripting
CVSS 6.1
kimai2 < 1.16.3 - Stored Cross-Site Scripting
CVSS 9.0
kimai2 < 1.16.2 - Improper Access Control
CVSS 6.5
Kimai < 1.14.1 - CSV Injection via Timesheet Description Field
CVSS 7.8
Kimai < 2.1.0 - Server-Side Template Injection and Remote Code Execution via Twig File Upload
CVSS 7.2
Kimai < 2.46.0 - Authenticated Information Disclosure via Twig Template Injection
CVSS 6.8