SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-43515

CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai.

HIGH 7.8EPSS 1.01%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.01%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By filling the Description field with malicious payload, it will be mistreated while exporting to a CSV file.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
1.01% probability · 61th percentile
CISA KEV
Not listed
Weakness
CWE-1236
Affected
kimai/kimai
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.