Impact
Kimai versions prior to 2.62.0 allow an authenticated user with the roles view_other_timesheet and edit_other_timesheet to create timesheet records for team members through the QuickEntry form. The application fails to verify whether the user has permission to create timesheets for others, so an attacker can manipulate data that should be restricted to the creator or an authorized administrator. This solely grants unauthorized data modification but does not expose system code or credentials.
Affected Systems
The vulnerability affects the Kimai time‑tracking application from the vendor kimai. Any installation of Kimai running a version earlier than 2.62.0 is affected. Earlier releases such as 2.61.x and below are vulnerable.
Risk and Exploitability
With a CVSS score of 8.7 the flaw is considered high severity. No EPSS score is published, so the current exploitation probability cannot be quantified, and the vulnerability is not yet listed in the CISA KEV catalog. It can be exploited by any authenticated user who has the view_other_timesheet and edit_other_timesheet permissions, which are typically granted to team leads or managers. The attack vector is an in‑application web form, requiring no external network access beyond normal business usage.
OpenCVE Enrichment