PT-2026-81914 · Kimai · Kimai
CVSS v4.0
2.0
Low
| Vector | AV:N/AC:H/AT:P/PR:H/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Kimai versions prior to 2.53.0
Description
The Twig invoice template sandbox fails to block sensitive User methods. This allows users with template creation permissions to call the
getApiToken() and getPlainApiToken() functions, leading to the leakage of hashed API tokens within the rendered invoice output.Recommendations
Update to version 2.53.0 or later.
Exploit
Fix
Code Injection
Incomplete List of Disallowed Inputs
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kimai