
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-53957 is a SameSite cookie vulnerability (CWE-1275) in Kimai version 1.30.10, a popular open-source time-tracking application. The flaw allows attackers to steal user session cookies by tricking victims into executing a crafted PHP script that captures and writes session cookie information to a file, enabling session hijacking. The CVE was assigned by VulnCheck and published on December 19, 2025, with NVD initial analysis completed February 19, 2026. It carries a CVSS v3.1 base score of 8.8 (High) per NIST NVD, and a CVSS v4.0 base score of 8.5 (High) per VulnCheck (VulnCheck Advisory, Kimai Release).
The vulnerability is classified as CWE-1275 (Sensitive Cookie with Improper SameSite Attribute), meaning Kimai 1.30.10 fails to properly configure the SameSite attribute on session cookies, leaving them exposed to cross-site request scenarios. An attacker exploits this by crafting a malicious PHP script that, when executed by a victim (e.g., via phishing or social engineering), captures the victim's session cookie and writes it to an attacker-controlled file. The attack requires no privileges on the target system but does require user interaction — the victim must be tricked into running the malicious script. A public proof-of-concept exploit is available on Exploit-DB (Exploit-DB PoC, VulnCheck Advisory).
Successful exploitation enables complete account compromise through session hijacking, allowing an attacker to impersonate a legitimate Kimai user without requiring their credentials. An attacker in possession of a stolen session cookie can perform any action the victim is authorized to perform, including accessing time-tracking records, project data, and potentially administrative functions depending on the victim's role. While availability impact is rated as none (the application itself is not disrupted), confidentiality and integrity are both rated High, reflecting the risk of unauthorized data access and manipulation (VulnCheck Advisory).
A public proof-of-concept exploit is available on Exploit-DB (exploit ID 51278), added to NVD references on February 19, 2026. There is no current evidence of active in-the-wild exploitation or known threat actor attribution. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.039% (0.000390), indicating a low probability of exploitation in the near term (Exploit-DB PoC, Feedly).
SameSite cookie attribute to allow cross-site cookie access.curl with the Cookie header) to authenticate to the Kimai instance as the victim, gaining full access to their account (Exploit-DB PoC, VulnCheck Advisory).Organizations should upgrade Kimai beyond version 1.30.10 to a patched release as the primary remediation step, as patches are available for versions after 1.30.10 (Kimai Release). As interim mitigations, administrators should implement network-level controls to restrict access to Kimai deployments (e.g., VPN or IP allowlisting), and educate users about phishing and the risks of executing unknown scripts. Additional session security measures such as short session timeouts, IP-based session binding, and monitoring for anomalous session activity are also recommended (VulnCheck Advisory).
The vulnerability received coverage from The Hacker Wire, which published an article titled "Critical Session Hijacking Vulnerability CVE-2023-53957 Strikes Kimai with SameSite Flaw," and was also highlighted in their weekly roundup for December 14–21, 2025 (The Hacker Wire). The CVE was also noted in a CISA vulnerability bulletin for the week of December 15, 2025. Social media activity was observed on Mastodon (infosec.exchange) and Bluesky, though no significant researcher controversy or vendor dispute has been noted.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."