{"id":"CVE-2021-4033","aliases":["GHSA-4jwx-78vx-gm6g"],"url":"https://o3.security/vulnerability/CVE-2021-4033","summary":"Cross-Site Request Forgery in kimai2","details":"CSRF in saving invoices / modifying status of invoices (pending and cancel only)","published":"2021-12-09T20:15:08.357Z","modified":"2026-08-27T08:40:40.475654Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"},"epss":{"score":0.00505,"percentile":0.41056,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"kevinpapst/kimai2","fixedVersion":"1.16.7"}],"fix":{"url":"https://github.com/kevinpapst/kimai2/commit/1da26e041df62c10bd8075d78f2db7854d3eee07","label":"kevinpapst/kimai2@1da26e0"},"references":[{"type":"FIX","url":"https://github.com/kevinpapst/kimai2/commit/1da26e041df62c10bd8075d78f2db7854d3eee07"},{"type":"EVIDENCE","url":"https://huntr.dev/bounties/e05be1f7-d00c-4cfd-9390-ccd9d1c737b7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-4033"},{"type":"PACKAGE","url":"https://github.com/kevinpapst/kimai2"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T08:40:40.475654Z"}}