CVE-2021-43515
HIGHKimai < 1.14.1 - CSV Injection via Timesheet Description Field
Title source: llmDescription
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By filling the Description field with malicious payload, it will be mistreated while exporting to a CSV file.
References (1)
Core 1
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/kevinpapst/kimai2/commit/dad1b8b772947f1596175add1b4f33b791705507#diff-6774f5865dbaf8bc6c55b75bd92e6f9950ebe7834aa2efd828a19fd637e667cf
Scores
CVSS v3
7.8
EPSS
0.0101
EPSS Percentile
58.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-1236
Status
published
Products (2)
kevinpapst/kimai2
0 - 1.14.1Packagist
kimai/kimai
< 1.14.1
Published
Apr 08, 2022
Tracked Since
Feb 18, 2026