Description
Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP script that captures and writes session cookie information to a file, enabling potential session hijacking.
Problem types
Sensitive Cookie with Improper SameSite Attribute
Product status
Credits
nu11secur1ty
References
www.exploit-db.com/exploits/51278 (ExploitDB-51278)
github.com/kimai/kimai/releases/tag/1.30.10 (Official Product Homepage)
www.vulncheck.com/...-cookie-vulnerability-session-hijacking (VulnCheck Advisory: Kimai 1.30.10 SameSite Cookie Vulnerability Session Hijacking)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.