MEDIUM
kevinpapst
CVE published 2026-02-11
CVE-2019-25317
CVE-2019-25317 is a persistent cross-site scripting (XSS) vulnerability in Kimai 2, which allows attackers to inject malicious scripts into timesheet descriptions. The vulnerability can be exploited by inserting SVG-based XSS payloads in the description field, leading to arbitrary JavaScript execution when the page is loaded and viewed by other users.