Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown
CVE-2024-29200
Disclosure Date: March 28, 2024 (last updated January 05, 2025)
Kimai is a web-based multi-user time-tracking application. The permission `view_other_timesheet` performs differently for the Kimai UI and the API, thus returning unexpected data through the API. When setting the `view_other_timesheet` permission to true, on the frontend, users can only see timesheet entries for teams they are a part of. When requesting all timesheets from the API, however, all timesheet entries are returned, regardless of whether the user shares team permissions or not. This vulnerability is fixed in 2.13.0.
0
Attacker Value
Unknown
CVE-2023-46245
Disclosure Date: October 31, 2023 (last updated January 12, 2024)
Kimai is a web-based multi-user time-tracking application. Versions prior to 2.1.0 are vulnerable to a Server-Side Template Injection (SSTI) which can be escalated to Remote Code Execution (RCE). The vulnerability arises when a malicious user uploads a specially crafted Twig file, exploiting the software's PDF and HTML rendering functionalities. Version 2.1.0 enables security measures for custom Twig templates.
0
Attacker Value
Unknown
CVE-2020-19825
Disclosure Date: February 15, 2023 (last updated October 08, 2023)
Cross Site Scripting (XSS) vulnerability in kevinpapst kimai2 1.30.0 in /src/Twig/Runtime/MarkdownExtension.php, allows attackers to gain escalated privileges.
0
Attacker Value
Unknown
CVE-2021-43515
Disclosure Date: April 08, 2022 (last updated February 23, 2025)
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By filling the Description field with malicious payload, it will be mistreated while exporting to a CSV file.
0
Attacker Value
Unknown
CVE-2021-4033
Disclosure Date: December 09, 2021 (last updated February 23, 2025)
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
0
Attacker Value
Unknown
CVE-2021-3983
Disclosure Date: December 01, 2021 (last updated February 23, 2025)
kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
0
Attacker Value
Unknown
CVE-2021-3992
Disclosure Date: December 01, 2021 (last updated February 23, 2025)
kimai2 is vulnerable to Improper Access Control
0
Attacker Value
Unknown
CVE-2021-3985
Disclosure Date: December 01, 2021 (last updated February 23, 2025)
kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
0
Attacker Value
Unknown
CVE-2021-3963
Disclosure Date: November 19, 2021 (last updated February 23, 2025)
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
0
Attacker Value
Unknown
CVE-2021-3957
Disclosure Date: November 19, 2021 (last updated February 23, 2025)
kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
0