Impact
An, customer, or activity can change the rate used for billing because the system separately resolves the parent object’s identifier and the attacker‑selected child rate identifier without verifying that the chosen rate actually belongs to that parent. The flaw allows pairing a rate record that does not belong to the specified project, customer, or activity and persisting the change in the kimai2_*_rates tables. This results in an integrity violation, where legitimate billing data can be altered to overcharge or undercharge customers, potentially causing financial loss or contractual disputes.
Affected Systems
The vulnerability affects the Kimai time tracking application, specifically all versions prior to 2.57.0 as released by the Kimai project.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% suggests exploitation is unlikely, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated and have editing rights for at least one parent object, and to submit a crafted request that points the rate ID to a record not owned by that parent. The vulnerability does not provide remote code execution or elevation of privilege, but it can lead to financial damage.
OpenCVE Enrichment
Github GHSA