Impact
Kimai is an open‑source time‑tracking application that, before version 2.57.0, allowed GET or POST requests to /en/admin/activity/create/{project} or /en/admin/project/create/{customer} to create activities or projects by only requiring the generic create_activity or create_project capability. The system fails to verify the requesting user’s edit rights on the specified project or customer. A user who knows a valid project.id or customer identifier can leverage the preset‑parent creation logic in ActivityController or ProjectController to persist a new child object under an unauthorized parent time‑entry, rate, reporting, and billing data. This improper authorization flaw (CWE‑639, CWE‑862) can be exploited to tamper with critical business information.
Affected Systems
All installations of Kimai up through version 2.56.x are affected. The specific endpoints are /en /en/admin/project/create/{customer}. The official fix is released in version 2.57.0. Any environment running a pre‑2.57.0 build is vulnerable if guess or enumerate valid project or customer identifiers.
Risk and Exploitability
The CVSS score of 5.3 denotes moderate severity. The EPSS score being under 1% indicates a low probability of exploitation in current threat landscapes, and KEV does not list this issue, suggesting it is not a widely observed exploit. However, the attack vector is straightforward: an attacker who can access the application with a user that holds create rights can supply any known project or customer ID and add a new childuting configuration data and potentially affecting revenue or audit trails.
OpenCVE Enrichment
Github GHSA