Impact
Kimai prior to version 2.57.0 allowed authenticated users with the edit_own_timesheet permission to modify timesheet entries via PATCH / POST endpoints. Through the TimesheetApiEditForm and FormTrait, and ProjectRepository::getQueryBuilderForFormType() placed that identifier in an unconditional OR branch, bypassing the team access criteria. As a result, any authenticated user could assign a timesheet to a project outside the user’s teams, thereby persisting unauthorized project attribution and accessing project and customer metadata via the GET / api/timesheets/{id}?full=true endpoint. The issue was addressed by adding project validation in TimesheetTeamAccessValidator in version 2.57.0. This flaw represents a privilege‑escalation and data‑disclosure vulnerability (CWE‑639).
Affected Systems
The vulnerability affects the Kimai time‑tracking application versions before 2.57.0. Users who are authenticated and hold the edit_own_timesheet role can exploit the flaw to assign timesheets to projects outside their teams. The issue was fixed in release 2.57.0; all later versions are not affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is below 1 %, suggesting a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. An attacker only needs valid credentials and the edit_own_timesheet role to execute the attack. While the flaw does not provide remote code execution, it enables unauthorized data modification and disclosure, potentially facilitating further attacks if combined with other weaknesses. Because the issue is reachable via the standard REST API, it can be triggered from any client possessing the required permissions.
OpenCVE Enrichment
Github GHSA