Impact
Kimai versions prior to 2.57.0 are vulnerable to an improper authorization flaw in the add and remove favorite timesheet endpoints. An authenticated user can reference another user’s timesheet identifier to add or remove entries from that user’s favorite list, allowing cross‑user business‑state tampering. This flaw leads to unauthorized modification of another user’s data without requiring administrative privileges. The weakness is a typical access‑control bypass, mapped to CWE‑639.
Affected Systems
The vulnerability affects installations of Kimai identified by the vendor product pair kimai:kimai. The affected versions are all releases before 2.57.0. Administrators or users with standard account privileges who can run the add or remove favorite endpoints are impacted.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity with a high impact and a reasonably quick exploitation path. The EPSS score is not available, so the exploit probability cannot be quantified, but the lack of a KEV listing suggests no widespread active exploitation was recorded at the time of this analysis. The attack vector is inferred to be through the web API or UI; an attacker must be authenticated to use the endpoints. Once authenticated, they can target any other user by specifying that user’s timesheet ID, enabling them to affect that user’s business state without setting higher privileges.
OpenCVE Enrichment