PatchSiren

kevinpapst CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM kevinpapst CVE published 2026-02-11

CVE-2019-25317

CVE-2019-25317 is a persistent cross-site scripting (XSS) vulnerability in Kimai 2, which allows attackers to inject malicious scripts into timesheet descriptions. The vulnerability can be exploited by inserting SVG-based XSS payloads in the description field, leading to arbitrary JavaScript execution when the page is loaded and viewed by other users.