Nixpkgs Security Tracker

Login with GitHub

Suggestion detail

Dismissed
(browse all)
updated 6 days, 13 hours ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse dismissed
Kimai 2- persistent cross-site scripting (XSS)

Kimai 2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into timesheet descriptions. Attackers can insert SVG-based XSS payloads in the description field to execute arbitrary JavaScript when the page is loaded and viewed by other users.

Affected products

Kimai
  • ==2

Matching in nixpkgs

Package maintainers

Upstream patch: https://github.com/kimai/kimai/commit/a0e8aa3a435717187fb12210242dab1b7c97ff3f

Current stable branch was never impacted.