Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown

CVE-2024-29200

Disclosure Date: March 28, 2024 (last updated January 05, 2025)
Kimai is a web-based multi-user time-tracking application. The permission `view_other_timesheet` performs differently for the Kimai UI and the API, thus returning unexpected data through the API. When setting the `view_other_timesheet` permission to true, on the frontend, users can only see timesheet entries for teams they are a part of. When requesting all timesheets from the API, however, all timesheet entries are returned, regardless of whether the user shares team permissions or not. This vulnerability is fixed in 2.13.0.
0
Attacker Value
Unknown

CVE-2023-46245

Disclosure Date: October 31, 2023 (last updated January 12, 2024)
Kimai is a web-based multi-user time-tracking application. Versions prior to 2.1.0 are vulnerable to a Server-Side Template Injection (SSTI) which can be escalated to Remote Code Execution (RCE). The vulnerability arises when a malicious user uploads a specially crafted Twig file, exploiting the software's PDF and HTML rendering functionalities. Version 2.1.0 enables security measures for custom Twig templates.
Attacker Value
Unknown

CVE-2020-19825

Disclosure Date: February 15, 2023 (last updated October 08, 2023)
Cross Site Scripting (XSS) vulnerability in kevinpapst kimai2 1.30.0 in /src/Twig/Runtime/MarkdownExtension.php, allows attackers to gain escalated privileges.
Attacker Value
Unknown

CVE-2021-43515

Disclosure Date: April 08, 2022 (last updated February 23, 2025)
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By filling the Description field with malicious payload, it will be mistreated while exporting to a CSV file.
Attacker Value
Unknown

CVE-2021-4033

Disclosure Date: December 09, 2021 (last updated February 23, 2025)
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
Attacker Value
Unknown

CVE-2021-3983

Disclosure Date: December 01, 2021 (last updated February 23, 2025)
kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Attacker Value
Unknown

CVE-2021-3992

Disclosure Date: December 01, 2021 (last updated February 23, 2025)
kimai2 is vulnerable to Improper Access Control
Attacker Value
Unknown

CVE-2021-3985

Disclosure Date: December 01, 2021 (last updated February 23, 2025)
kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Attacker Value
Unknown

CVE-2021-3963

Disclosure Date: November 19, 2021 (last updated February 23, 2025)
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
Attacker Value
Unknown

CVE-2021-3957

Disclosure Date: November 19, 2021 (last updated February 23, 2025)
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)