CVE-2023-53957
Published: 19 December 2025
Description
Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP script that captures and writes session cookie information to a file, enabling potential…
more
session hijacking.
Mitigating Controls (NIST 800-53 r5)AI
Requires timely identification, reporting, and patching of the SameSite cookie flaw in Kimai, directly preventing session cookie theft and hijacking.
Mandates secure baseline configuration settings for session cookies, including proper SameSite attributes to block cross-site requests that steal cookies.
Implements mechanisms to protect session authenticity against interception and replay, mitigating risks from stolen session cookies via SameSite enforcement.
Security SummaryAI
CVE-2023-53957 is a SameSite cookie vulnerability in Kimai version 1.30.10, a PHP-based time-tracking application. The flaw allows attackers to steal user session cookies by exploiting improper cookie attributes, specifically through a crafted PHP script that captures and writes session cookie data to a file on the server. This issue is rated critical with a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and is associated with CWE-1275.
Any unauthenticated attacker with network access can exploit this vulnerability remotely with low complexity and no privileges required. By tricking victims into executing the crafted PHP script—potentially via social engineering or cross-site scripting—the attacker can capture valid session cookies, enabling session hijacking and unauthorized access to the victim's account in Kimai.
Advisories and references recommend mitigation through patching. The Kimai GitHub release page for tag 1.30.10 likely details fixes for this issue, urging users to upgrade to a patched version. An exploit is publicly available on Exploit-DB (ID 51278), and VulnCheck's advisory highlights the SameSite cookie misconfiguration leading to session hijacking, emphasizing immediate updates to prevent exploitation.
Details
- CWE(s)
Affected Products
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
The vulnerability in a public-facing web application (T1190) enables unauthenticated remote exploitation to steal web session cookies (T1539) via SameSite misconfiguration, facilitating session hijacking.