Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP script that captures and writes session cookie information to a file, enabling potential session hijacking.
{
"cwe_ids": [
"CWE-1275"
],
"github_reviewed": true,
"github_reviewed_at": "2026-02-20T18:25:02Z",
"nvd_published_at": "2025-12-19T21:15:52Z",
"severity": "HIGH"
}