<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=Kimai_1.14_-_CSV%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E</id>
	<title>Kimai 1.14 - CSV注入漏洞 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=Kimai_1.14_-_CSV%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=Kimai_1.14_-_CSV%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E&amp;action=history"/>
	<updated>2026-04-10T12:03:37Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=Kimai_1.14_-_CSV%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E&amp;diff=1905&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;==EXP== &lt;pre&gt; # Exploit Title: Kimai 1.14 - CSV Injection # Date: 26/04/2021 # Exploit Author: Mohammed Aloraimi # Vendor Homepage: https://www.kimai.org/ # Software Link: htt...&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=Kimai_1.14_-_CSV%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E&amp;diff=1905&amp;oldid=prev"/>
		<updated>2021-04-27T11:42:35Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;==EXP== &amp;lt;pre&amp;gt; # Exploit Title: Kimai 1.14 - CSV Injection # Date: 26/04/2021 # Exploit Author: Mohammed Aloraimi # Vendor Homepage: https://www.kimai.org/ # Software Link: htt...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==EXP==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Exploit Title: Kimai 1.14 - CSV Injection&lt;br /&gt;
# Date: 26/04/2021&lt;br /&gt;
# Exploit Author: Mohammed Aloraimi&lt;br /&gt;
# Vendor Homepage: https://www.kimai.org/&lt;br /&gt;
# Software Link: https://github.com/kevinpapst/kimai2&lt;br /&gt;
# Version: 1.14 &amp;lt;https://github.com/kevinpapst/kimai2/releases/tag/1.14&amp;gt;&lt;br /&gt;
# Payload:  @SUM(1+9)*cmd|' /C calc'!A0&lt;br /&gt;
# Tested on: Win10x64&lt;br /&gt;
# Proof Of Concept:&lt;br /&gt;
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in&lt;br /&gt;
creating new timesheet in Kimai. By filling the Description field with malicious&lt;br /&gt;
payload, it will be mistreated while exporting to a CSV file.&lt;br /&gt;
&lt;br /&gt;
To exploit this vulnerability:&lt;br /&gt;
1- Login as user.&lt;br /&gt;
2- Create new timesheet.&lt;br /&gt;
3- Fill the description with the malicious payload.&lt;br /&gt;
4- Save the timesheet.&lt;br /&gt;
5- Export it via CSV.&lt;br /&gt;
6- Open the CSV file, allow all popups and our payload is executed(calculator is opened).&lt;br /&gt;
            &lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>