在 Kimai 2.53.0 版本之前,Twig 发票模板沙箱未能阻止对敏感的用户方法调用,导致管理员能够调用 getApiToken() 和 getPlainApiToken() 方法。拥有模板创建权限的攻击者可以将这些方法调用嵌入发票模板中,从而在渲染后的发票输出中泄露已哈希的 API 令牌。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80193 | 8.8 HIGH | Kimai before 2.62.0 Authorization Bypass via QuickEntry |
| CVE-2026-80202 | 8.8 HIGH | Kimai before 2.56.0 Authorization Bypass via TimesheetVoter |
| CVE-2026-80196 | 7.5 HIGH | Kimai before 2.58.0 Authentication Bypass via Password Reset Link |
| CVE-2026-80198 | 7.5 HIGH | Kimai before 2.56.0 Information Disclosure via config() Twig Function |
| CVE-2026-80195 | 5.4 MEDIUM | Kimai before 2.63.0 Team Membership Removal via API |
| CVE-2026-80194 | 4.3 MEDIUM | Kimai before 2.64.0 Missing Authorization via ProjectViewController export |
| CVE-2026-80197 | 4.3 MEDIUM | Kimai before 2.57.0 Improper Authorization via Favorite Endpoints |
| CVE-2026-80199 | 3.7 LOW | Kimai before 2.54.0 Username Enumeration via Timing Oracle |
| CVE-2026-80200 | Kimai before 2.53.0 Open Redirect via RelayState |
No comments yet