Description
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By filling the Description field with malicious payload, it will be mistreated while exporting to a CSV file.
Scores
CVSS v3
7.8
EPSS
0.0050
EPSS Percentile
66.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-1236
Status
published
Products (2)
kevinpapst/kimai2
0 - 1.14.1Packagist
kimai/kimai
< 1.14.1
Published
Apr 08, 2022
Tracked Since
Feb 18, 2026