CVE Vulnerabilities

CVE-2023-53957

Sensitive Cookie with Improper SameSite Attribute

Published: Dec 19, 2025 | Modified: Dec 19, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP script that captures and writes session cookie information to a file, enabling potential session hijacking.

Weakness

The SameSite attribute for sensitive cookies is not set, or an insecure value is used.

Potential Mitigations

References