Kimai 是一款开源的时间跟踪应用程序。在 2.57.0 版本之前, 和 接口通过 和 接受用户可控的项目标识符,而 方法将该标识符置于一个无条件的 OR 分支中,从而绕过了团队访问权限的控制条件。因此,任何拥有 权限的已认证用户可以将自己所有的工时记录关联到不属于其所属团队的项目,从而持久化保存未授权的项目归属信息,并可通过 检索项目和客户元数据。 现在会检查被修改的项目和活动关联是否符合当前团队的访问权限。该问题已在 2.57.0 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-52824 | 9.1 CRITICAL | Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover |
| CVE-2026-52827 | 7.1 HIGH | Kimai: Two-factor authentication bypass on the Kimai API |
| CVE-2026-52819 | 6.3 MEDIUM | Kimai: Teamlead authorization bypass in GET /api/timesheets allows reading other users' ti |
| CVE-2026-52825 | 5.3 MEDIUM | Kimai: Improper Authorization in Kimai Team Member and Team Activity Assignment APIs Allow |
| CVE-2026-52823 | 5.3 MEDIUM | Kimai: Login CSRF in Kimai Timesheet Stop and Restart API Endpoints Allows Unauthorized St |
| CVE-2026-52821 | 5.3 MEDIUM | Kimai: Improper Authorization in Kimai Activity Creation with Preset Project Allows Creati |
| CVE-2026-52826 | 5.3 MEDIUM | Kimai: Improper Authorization in Kimai Project, Customer, and Activity Rate Edit Endpoints |
| CVE-2026-52828 | 5.3 MEDIUM | Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD Access |
| CVE-2026-52822 | 5.3 MEDIUM | Kimai: Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timeshee |
No comments yet