Kimai 是一款开源的时间追踪应用程序。在 2.57.0 版本之前,GET /api/timesheets 列表端点允许拥有 权限的调用者通过 和 参数指定目标用户,但未对请求者是否通过 权限或确认该请求者(具有 ROLE_TEAMLEAD 角色)是否领导了包含每个目标用户的团队进行验证。 具体而言, 将解析后的用户直接添加到查询条件中,而项目和客户过滤仍然允许访问未加范围限制的项目或仅具有普通团队成员资格的项目中的记录。这导致团队负责人(teamlead)能够获取其他用户的描述信息、时间数据、标签、费率(rat
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-52824 | 9.1 CRITICAL | Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover |
| CVE-2026-52827 | 7.1 HIGH | Kimai: Two-factor authentication bypass on the Kimai API |
| CVE-2026-52825 | 5.3 MEDIUM | Kimai: Improper Authorization in Kimai Team Member and Team Activity Assignment APIs Allow |
| CVE-2026-52820 | 5.3 MEDIUM | Kimai: Timesheet PATCH/POST allows assigning to project outside user's team via query_buil |
| CVE-2026-52823 | 5.3 MEDIUM | Kimai: Login CSRF in Kimai Timesheet Stop and Restart API Endpoints Allows Unauthorized St |
| CVE-2026-52821 | 5.3 MEDIUM | Kimai: Improper Authorization in Kimai Activity Creation with Preset Project Allows Creati |
| CVE-2026-52826 | 5.3 MEDIUM | Kimai: Improper Authorization in Kimai Project, Customer, and Activity Rate Edit Endpoints |
| CVE-2026-52828 | 5.3 MEDIUM | Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD Access |
| CVE-2026-52822 | 5.3 MEDIUM | Kimai: Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timeshee |
No comments yet