PT-2026-81915 · Kimai · Kimai
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Kimai versions prior to 2.56.0
Description
An issue exists where team-membership checks are not enforced in the
voteOnAttribute() function of TimesheetVoter. This function maps permissions only to own timesheet or other timesheet. Consequently, any authenticated user with ROLE TEAMLEAD or a role possessing edit other timesheet or delete other timesheet permissions can read, modify, and permanently delete timesheets of any user across the entire system via the API, regardless of whether they belong to the same team. This is facilitated by the fact that timesheet IDs are sequential integers and easily enumerable.Recommendations
Update to version 2.56.0 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kimai