Kimai 2.56.0 之前版本在沙盒化的发票和导出模板中未能限制 config() Twig 函数,导致管理员可以访问任意配置密钥。拥有管理员权限的攻击者可以上传恶意模板,将服务器范围内的秘密信息(如 LDAP 绑定密码和 SAML 私钥)提取到发票或导出文档中,这些文档可以被低权限用户访问。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-80193 | 8.8 HIGH | Kimai before 2.62.0 Authorization Bypass via QuickEntry |
| CVE-2026-80202 | 8.8 HIGH | Kimai before 2.56.0 Authorization Bypass via TimesheetVoter |
| CVE-2026-80196 | 7.5 HIGH | Kimai before 2.58.0 Authentication Bypass via Password Reset Link |
| CVE-2026-80195 | 5.4 MEDIUM | Kimai before 2.63.0 Team Membership Removal via API |
| CVE-2026-80194 | 4.3 MEDIUM | Kimai before 2.64.0 Missing Authorization via ProjectViewController export |
| CVE-2026-80197 | 4.3 MEDIUM | Kimai before 2.57.0 Improper Authorization via Favorite Endpoints |
| CVE-2026-80199 | 3.7 LOW | Kimai before 2.54.0 Username Enumeration via Timing Oracle |
| CVE-2026-80201 | 2.0 LOW | Kimai before 2.53.0 API Token Leakage via Invoice Template |
| CVE-2026-80200 | Kimai before 2.53.0 Open Redirect via RelayState |
No comments yet