kimai是kimai个人开发者的一个基于网络的多用户时间跟踪应用程序。 kimai 2.54.0之前版本存在安全漏洞,该漏洞源于Team API端点使用错误注解导致TeamVoter弃权,可能导致任何具有edit_team权限的用户修改任意团队。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-44298 | 4.1 MEDIUM | Kimai: Arbitrary file read in invoice PDF renderer (admin) |
| CVE-2026-42267 | Kimai: Formula Injection via tag names in XLSX export |
No comments yet