CVE-2023-53957

CRITICAL

Kimai <1.30.10 - XSS

Title source: llm

Description

Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP script that captures and writes session cookie information to a file, enabling potential session hijacking.

Exploits (1)

exploitdb WORKING POC
by nu11secur1ty · textwebappsphp
https://www.exploit-db.com/exploits/51278

Scores

CVSS v3 9.8
EPSS 0.0024
EPSS Percentile 46.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-1275
Status published
Products (3)
kimai/kimai 1.30.10
kimai/kimai 0Packagist
Kimai/Kimai 1.30.10
Published Dec 19, 2025
Tracked Since Feb 18, 2026