{"id":"CVE-2021-3983","aliases":["GHSA-67c7-5v9j-227r"],"url":"https://o3.security/vulnerability/CVE-2021-3983","summary":"Cross-site Scripting in kimai2","details":"kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","published":"2021-12-01T12:15:07.683Z","modified":"2026-07-08T22:14:06.729698Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"kevinpapst/kimai2","fixedVersion":"1.16.3"}],"fix":{"url":"https://github.com/kevinpapst/kimai2/commit/89bfa82c61da0d3639e4038e689e25467baac8a0","label":"kevinpapst/kimai2@89bfa82"},"references":[{"type":"FIX","url":"https://github.com/kevinpapst/kimai2/commit/89bfa82c61da0d3639e4038e689e25467baac8a0"},{"type":"FIX","url":"https://huntr.dev/bounties/c96f3480-dccf-4cc2-99a4-d2b3a7462413"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T22:14:06.729698Z"}}