CVE-2023-53957
CRITICALKimai 1.30.10 - Sensitive Cookie with Improper SameSite Attribute
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-53957. PoCs published by nu11secur1ty.
AI-analyzed exploit summary This exploit demonstrates a SameSite cookie vulnerability in Kimai 1.30.10, allowing session hijacking by tricking a victim into executing a malicious script that steals their session cookie.
Description
Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP script that captures and writes session cookie information to a file, enabling potential session hijacking.
Exploits (1)
This exploit demonstrates a SameSite cookie vulnerability in Kimai 1.30.10, allowing session hijacking by tricking a victim into executing a malicious script that steals their session cookie.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H