PT-2026-81909 · Kimai · Kimai
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Kimai versions prior to 2.58.0
Description
An authentication bypass exists because password reset links remain valid after a password has been changed. This occurs because the
LoginLink signature only includes the user id and does not incorporate the password hash. An attacker who intercepts or caches a password reset link can use it up to two additional times within a one-hour window to gain unauthorized access to the user account.Recommendations
Update to version 2.58.0.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kimai