在 Kimai 版本低于 2.62.0 的情况下,QuickEntry 控制器在创建新的工时记录时未能正确验证“创建其他人员的工时表”(create_other_timesheet)权限。具备“查看其他人员工时表”(view_other_timesheet)和“编辑其他人员工时表”(edit_other_timesheet)权限的已认证用户,可以通过提交 QuickEntry 表单来创建属于团队其他成员的工时记录,从而绕过系统在其他地方实施的授权检查机制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-80202 | 8.8 HIGH | Kimai before 2.56.0 Authorization Bypass via TimesheetVoter |
| CVE-2026-80196 | 7.5 HIGH | Kimai before 2.58.0 Authentication Bypass via Password Reset Link |
| CVE-2026-80198 | 7.5 HIGH | Kimai before 2.56.0 Information Disclosure via config() Twig Function |
| CVE-2026-80195 | 5.4 MEDIUM | Kimai before 2.63.0 Team Membership Removal via API |
| CVE-2026-80194 | 4.3 MEDIUM | Kimai before 2.64.0 Missing Authorization via ProjectViewController export |
| CVE-2026-80197 | 4.3 MEDIUM | Kimai before 2.57.0 Improper Authorization via Favorite Endpoints |
| CVE-2026-80199 | 3.7 LOW | Kimai before 2.54.0 Username Enumeration via Timing Oracle |
| CVE-2026-80201 | 2.0 LOW | Kimai before 2.53.0 API Token Leakage via Invoice Template |
| CVE-2026-80200 | Kimai before 2.53.0 Open Redirect via RelayState |
No comments yet