Impact
Kimai, an open‑source time‑tracking application, is vulnerable in versions prior to 2.58.0 due to authenticated cross‑site request forgery in default team‑creation shortcuts for projects, customers, and activities. These shortcuts are exposed through GET routes; they automatically create or reuse a Team, assign the current user as team‑lead, and bind the target object to that team. If a logged‑in user with the requisite permissions is tricked into visiting a malicious URL, the attacker can authorize changes to team, team‑lead, and object‑binding relationships, thereby altering the organization’s team and permission structure. This is a real authorization‑structure modification issue rather than a harmless UI shortcut.
Affected Systems
The affected product is Kimai, an open‑source time‑tracking application. Any deployment using a version earlier than 2.58.0 is vulnerable. Version 2.58.0 onward includes the fix.
Risk and Exploitability
The CVSS base score of 6.3 indicates a moderate risk. The EPSS score is <1%, suggesting a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no known active exploits at the time of analysis. The flaw requires the victim to be authenticated and to possess the permissions needed to create or modify teams. Based on the description, it is inferred that the likely attack vector is a malicious URL that an authenticated user with the necessary permissions is lured to. If successful, the attacker can alter team structure and permissions, potentially compromising the organization’s data access controls.
OpenCVE Enrichment
Github GHSA