Kimai 是一款开源的时间追踪应用。在 2.57.0 版本之前,针对 和 的 GET 或 POST 请求仅需具备通用的 或 权限即可执行,而不会校验用户对所传入的 Project 或 Customer 对象是否具有编辑权限。因此,知道有效 project.id 或 customer 标识符的用户可以利用 或 中的预设父级创建逻辑,在未获得授权的情况下,将新的子业务对象挂在一个未授权的父级之下,从而污染项目或客户配置,并影响后续的时间条目记录、费率、报表及计费行为。该问题已在 2.57.0 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-52824 | 9.1 CRITICAL | Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover |
| CVE-2026-52827 | 7.1 HIGH | Kimai: Two-factor authentication bypass on the Kimai API |
| CVE-2026-52819 | 6.3 MEDIUM | Kimai: Teamlead authorization bypass in GET /api/timesheets allows reading other users' ti |
| CVE-2026-52825 | 5.3 MEDIUM | Kimai: Improper Authorization in Kimai Team Member and Team Activity Assignment APIs Allow |
| CVE-2026-52820 | 5.3 MEDIUM | Kimai: Timesheet PATCH/POST allows assigning to project outside user's team via query_buil |
| CVE-2026-52823 | 5.3 MEDIUM | Kimai: Login CSRF in Kimai Timesheet Stop and Restart API Endpoints Allows Unauthorized St |
| CVE-2026-52826 | 5.3 MEDIUM | Kimai: Improper Authorization in Kimai Project, Customer, and Activity Rate Edit Endpoints |
| CVE-2026-52828 | 5.3 MEDIUM | Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD Access |
| CVE-2026-52822 | 5.3 MEDIUM | Kimai: Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timeshee |
No comments yet