Impact
Kimai’s TimesheetController exposes two GET endpoints—/api/timesheets/{id}/stop and /api/timesheets/{id}/restart—that modify the state of a timesheet without requiring a request‑forgery measure. The flaw allows a malicious party to induce a logged‑in user to click or otherwise trigger these URLs from attacker‑controlled content, causing the timesheet to be stopped or a historical entry to be restarted. Such unauthorized alterations can corrupt collective in‑house records, as well as downstream billing, reporting, approvals, and audit trails.
Affected Systems
The vulnerability affects the Kimai time‑tracking application prior to version 2.58.0. All versions before this release expose the vulnerable GET routes. The issue was remedied in Kimai 2.58.0, which removes or protects these endpoints.
Risk and Exploitability
The CVSS score is 5.3, indicating a moderate threat level. The EPSS score is below 1%, suggesting a low probability of exploitation at this time, and the flaw is not currently listed in the CISA KEV catalog. The attack vector requires an authenticated session; a CSRF vector can be executed by embedding or displaying the target URLs within hostile web content and persuading a user to load it. Existing safeguards such as strict same‑origin policies can mitigate the risk, but the lack of a CSRF token on these URIs removes the single most effective barrier against this form of attack.
OpenCVE Enrichment
Github GHSA