在 Kimai 版本低于 2.53.0 中,SAML 身份验证成功处理器存在一个开放重定向漏洞。该漏洞允许未经验证的 RelayState POST 参数被用作重定向目标。拥有 IdP(身份提供者)访问权限的攻擊者可以构造恶意的 RelayState 值,引导已通过认证的用户重定向到攻擊者控制的网站,从而实施凭据窃取或网络钓鱼攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80193 | 8.8 HIGH | Kimai before 2.62.0 Authorization Bypass via QuickEntry |
| CVE-2026-80202 | 8.8 HIGH | Kimai before 2.56.0 Authorization Bypass via TimesheetVoter |
| CVE-2026-80196 | 7.5 HIGH | Kimai before 2.58.0 Authentication Bypass via Password Reset Link |
| CVE-2026-80198 | 7.5 HIGH | Kimai before 2.56.0 Information Disclosure via config() Twig Function |
| CVE-2026-80195 | 5.4 MEDIUM | Kimai before 2.63.0 Team Membership Removal via API |
| CVE-2026-80194 | 4.3 MEDIUM | Kimai before 2.64.0 Missing Authorization via ProjectViewController export |
| CVE-2026-80197 | 4.3 MEDIUM | Kimai before 2.57.0 Improper Authorization via Favorite Endpoints |
| CVE-2026-80199 | 3.7 LOW | Kimai before 2.54.0 Username Enumeration via Timing Oracle |
| CVE-2026-80201 | 2.0 LOW | Kimai before 2.53.0 API Token Leakage via Invoice Template |
No comments yet