Kimai 2.56.0 之前的版本中,TimesheetVoter::voteOnAttribute() 方法未强制实施团队成员身份检查,该方法仅将权限映射到 own_timesheet(自己记录的工时表)或 other_timesheet(他人记录的工时表)。因此,任何拥有 ROLE_TEAMLEAD 角色(或具备 edit_other_timesheet / delete_other_timesheet 权限的角色)的已认证用户,均可通过 API 读取、修改并永久删除系统中任意用户的工时表记录,无论其是否属于
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-80193 | 8.8 HIGH | Kimai before 2.62.0 Authorization Bypass via QuickEntry |
| CVE-2026-80196 | 7.5 HIGH | Kimai before 2.58.0 Authentication Bypass via Password Reset Link |
| CVE-2026-80198 | 7.5 HIGH | Kimai before 2.56.0 Information Disclosure via config() Twig Function |
| CVE-2026-80195 | 5.4 MEDIUM | Kimai before 2.63.0 Team Membership Removal via API |
| CVE-2026-80194 | 4.3 MEDIUM | Kimai before 2.64.0 Missing Authorization via ProjectViewController export |
| CVE-2026-80197 | 4.3 MEDIUM | Kimai before 2.57.0 Improper Authorization via Favorite Endpoints |
| CVE-2026-80199 | 3.7 LOW | Kimai before 2.54.0 Username Enumeration via Timing Oracle |
| CVE-2026-80201 | 2.0 LOW | Kimai before 2.53.0 API Token Leakage via Invoice Template |
| CVE-2026-80200 | Kimai before 2.53.0 Open Redirect via RelayState |
No comments yet