CyberRota Analysis
AI-GeneratedVersions of Kimai prior to 2.65.0 are vulnerable to an authorization bypass in the REST API timesheet collection endpoint, allowing users with the view_other_timesheet permission to access timesheets associated with activities outside their designated teams. This flaw compromises data isolation and could lead to unauthorized exposure of sensitive timesheet information. Organizations utilizing Kimai should prioritize patching to mitigate potential data breaches and ensure compliance with access control policies.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Kimai versions before 2.65.0 contain an authorization bypass vulnerability in the REST API timesheet collection endpoint that fails to enforce activity-team access controls. Users with view_other_timesheet permission can list timesheets using activities restricted to teams they do not belong to, bypassing intended data isolation.