Kimai 2.61.0 至 2.62.9(即 2.63.0 之前)版本在 接口中无法为低权限用户禁用仅限管理员的工作合同偏好设置。尽管 Web 界面通过 管理员权限对这些劳动合同字段进行了访问控制,但在 2.61.0 中引入的 未做权限检查,直接将偏好设置为启用状态。因此,已认证的普通用户可通过 API 修改自己的仅限管理员的工作合同数据。该问题已在 2.63.0 中修复,修复方式为在 API 接口上应用相同的权限检查。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84807 | 5.4 MEDIUM | Kimai before 2.65.0 Authentication Bypass via Team Creation |
| CVE-2026-84806 | 5.4 MEDIUM | Kimai before 2.63.0 Authorization Bypass via Team Access Endpoints |
| CVE-2026-84804 | 5.4 MEDIUM | Kimai before 2.65.0 Authorization Bypass via Team Activity API |
| CVE-2026-84808 | 4.3 MEDIUM | Kimai before 2.65.0 Authorization Bypass via API Timesheet |
No comments yet