SameSite Cookie Vulnerability in Kimai Product by Kimai
CVE-2023-53957

8.5HIGH

Key Information:

Vendor

Kimai

Status
Vendor
CVE Published:
19 December 2025

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2023-53957?

The Kimai 1.30.10 version features a vulnerability related to SameSite cookies that poses a risk of session hijacking. Attackers can exploit this flaw by tricking users into executing a malicious PHP script, which captures session cookie information and writes it to a file. This potential breach allows unauthorized access to user sessions, enabling attackers to assume the identity of legitimate users and perform unauthorized actions within the application.

Affected Version(s)

Kimai 1.30.10

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

nu11secur1ty
.