KiMi是一款开源的时间追踪应用。在2.58.0版本之前, 和 这两个端点会验证团队领导(teamlead)是否有权限编辑团队,但未验证所引用的用户是否具备 权限,也未验证所引用的活动是否具备查看(view)权限。 团队领导可以将超出其可管理范围的(非其团队内的)用户或活动添加到一个可编辑的团队中,从而绕过 和 所强制实施的较窄选择范围。由此产生的关联关系可能被 以及其他基于团队的授权、可见性、报表和工作流逻辑所信赖,从而导致权限控制失效。 该问题已在2.58.0版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-52824 | 9.1 CRITICAL | Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover |
| CVE-2026-52827 | 7.1 HIGH | Kimai: Two-factor authentication bypass on the Kimai API |
| CVE-2026-52819 | 6.3 MEDIUM | Kimai: Teamlead authorization bypass in GET /api/timesheets allows reading other users' ti |
| CVE-2026-52820 | 5.3 MEDIUM | Kimai: Timesheet PATCH/POST allows assigning to project outside user's team via query_buil |
| CVE-2026-52823 | 5.3 MEDIUM | Kimai: Login CSRF in Kimai Timesheet Stop and Restart API Endpoints Allows Unauthorized St |
| CVE-2026-52821 | 5.3 MEDIUM | Kimai: Improper Authorization in Kimai Activity Creation with Preset Project Allows Creati |
| CVE-2026-52826 | 5.3 MEDIUM | Kimai: Improper Authorization in Kimai Project, Customer, and Activity Rate Edit Endpoints |
| CVE-2026-52828 | 5.3 MEDIUM | Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD Access |
| CVE-2026-52822 | 5.3 MEDIUM | Kimai: Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timeshee |
No comments yet