CVE Vulnerabilities

CVE-2023-53957

Sensitive Cookie with Improper SameSite Attribute

Published: Dec 19, 2025 | Modified: Feb 19, 2026
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP script that captures and writes session cookie information to a file, enabling potential session hijacking.

Weakness

The SameSite attribute for sensitive cookies is not set, or an insecure value is used.

Affected Software

NameVendorStart VersionEnd Version
KimaiKimai1.30.10 (including)1.30.10 (including)

Potential Mitigations

References