PT-2026-81906 · Kimai · Kimai
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kimai versions prior to 2.62.0
Description
An authorization bypass exists in the
QuickEntry controller during the creation of new timesheets. Authenticated users who possess view other timesheet and edit other timesheet permissions can create timesheet records for other team members by submitting the QuickEntry form, as the system fails to validate the create other timesheet permission.Recommendations
Update to version 2.62.0 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kimai