{"id":"CVE-2023-53957","summary":"Kimai 1.30.10 SameSite Cookie Vulnerability Session Hijacking","details":"Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP script that captures and writes session cookie information to a file, enabling potential session hijacking.","aliases":["GHSA-cv8h-r7r5-vwj9"],"modified":"2026-08-12T03:51:48.391251713Z","published":"2025-12-19T21:05:52.561Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-1275"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53957.json"},"references":[{"type":"WEB","url":"https://github.com/kimai/kimai/releases/tag/1.30.10"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53957.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-53957"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/kimai-samesite-cookie-vulnerability-session-hijacking"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/51278"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/kimai/kimai","events":[{"introduced":"6df135d54761aa70f951be059811028b97b9d12c"},{"fixed":"6df135d54761aa70f951be059811028b97b9d12c"}],"database_specific":{"cpe":"cpe:2.3:a:kimai:kimai:1.30.10:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.30.10"},{"last_affected":"1.30.10"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["1.30.10"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53957.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}