Kimai 2.54.0 之前的版本中,TokenAuthenticator 存在一个时序或acles 漏洞,允许未经身份验证的攻击者通过 X-AUTH-USER 头部枚举有效用户名。由于密码哈希处理仅对已存在的用户执行,攻击者可以通过测量响应时间的差异来枚举用户名,而系统缺乏登录速率限制(throttling)保护。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80193 | 8.8 HIGH | Kimai before 2.62.0 Authorization Bypass via QuickEntry |
| CVE-2026-80202 | 8.8 HIGH | Kimai before 2.56.0 Authorization Bypass via TimesheetVoter |
| CVE-2026-80196 | 7.5 HIGH | Kimai before 2.58.0 Authentication Bypass via Password Reset Link |
| CVE-2026-80198 | 7.5 HIGH | Kimai before 2.56.0 Information Disclosure via config() Twig Function |
| CVE-2026-80195 | 5.4 MEDIUM | Kimai before 2.63.0 Team Membership Removal via API |
| CVE-2026-80194 | 4.3 MEDIUM | Kimai before 2.64.0 Missing Authorization via ProjectViewController export |
| CVE-2026-80197 | 4.3 MEDIUM | Kimai before 2.57.0 Improper Authorization via Favorite Endpoints |
| CVE-2026-80201 | 2.0 LOW | Kimai before 2.53.0 API Token Leakage via Invoice Template |
| CVE-2026-80200 | Kimai before 2.53.0 Open Redirect via RelayState |
No comments yet