{"id":"CVE-2023-53957","title":"Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation","summary":"Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP script that captures and writes session c…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-1275"],"vendor":"kimai","product":"kimai","affected":["kimai = 1.30.10"],"published":"2025-12-19","updated":"2026-10-08","sourceUpdated":"2026-10-08T16:16:47.210","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-53957","references":[{"url":"https://github.com/kimai/kimai/releases/tag/1.30.10","label":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/51278","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/kimai-samesite-cookie-vulnerability-session-hijacking","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"total","timestamp":"2025-12-19T21:36:13.015775Z"},"epss":0.00592,"epssPercentile":0.46622,"ingestedAt":"2026-10-08T16:52:14.667Z","slug":"CVE-2023-53957","body":"## Overview\n\nKimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP script that captures and writes session cookie information to a file, enabling potential session hijacking.\n\n## Affected\n\n- `kimai = 1.30.10`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":66,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}