{"id":"CVE-2021-3957","aliases":["GHSA-2xwq-h7r9-6w27"],"url":"https://o3.security/vulnerability/CVE-2021-3957","summary":"Cross-site Scripting in kimai2","details":"kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)","published":"2021-11-19T12:15:08.977Z","modified":"2026-07-08T05:59:53.227153477Z","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"kevinpapst/kimai2","fixedVersion":"1.16"}],"fix":{"url":"https://github.com/kevinpapst/kimai2/commit/6b49535b523dcd36ec59462ee4e67e2b3a9151f3","label":"kevinpapst/kimai2@6b49535"},"references":[{"type":"FIX","url":"https://github.com/kevinpapst/kimai2/commit/6b49535b523dcd36ec59462ee4e67e2b3a9151f3"},{"type":"FIX","url":"https://huntr.dev/bounties/5fa3098a-ba02-45e0-af56-645e34dbc691"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:59:53.227153477Z"}}