Cross-Site Request Forgery (CSRF) in kevinpapst/kimai2
Valid
Reported on
Nov 15th 2021
Description
CSRF in deleting invoice templates
Proof of Concept
<a href="https://[KIMAi_URL]/en/invoice/template/7/delete">CLICK ME!</a>
Impact
This vulnerability is capable of tricking admin user to delete invoice templates.
We are processing your report and will contact the
kevinpapst/kimai2
team within 24 hours.
2 years ago
We have contacted a member of the
kevinpapst/kimai2
team and are waiting to hear back
2 years ago
2 years ago
InvoiceController.php#L457L467
has been validated
InvoiceTemplateSubscriber.php#L37L39
has been validated
to join this conversation