PT-2026-81913 · Kimai · Kimai
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Kimai versions prior to 2.53.0
Description
An open redirect issue exists in the SAML authentication success handler. The system accepts unvalidated
RelayState POST parameters as redirect destinations, allowing attackers with Identity Provider (IdP) access to redirect authenticated users to malicious URLs. This can be used to facilitate phishing attacks or credential theft.Recommendations
Update to version 2.53.0 or later.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kimai