Impact
Kimai versions prior to 2.56.0 do not restrict the config() function in sandboxed invoice and export templates, letting an attacker who can act with administrator permissions read arbitrary configuration keys. By uploading a crafted template, the attacker can embed sensitive server secrets such as LDAP bind passwords and SAML private keys into generated invoice or export documents, which are then viewable by lower‑privilege users. This results in a breach of confidentiality for credentials and secrets that the application holds.
Affected Systems
The vulnerability affects the Kimai time‑tracking application from the vendor Kimai, impacting all releases earlier than 2.56.0.
Risk and Exploitability
With a CVSS score of 8.7, the vulnerability poses a high‑impact information‑disclosure risk. The exploit requires administrative access to upload malicious templates; once in place, any lower‑privilege users who view generated documents can read the leaked secrets. There is no EPSS information and the issue is not currently listed in the CISA KEV catalog, but the high severity and the potential for credential theft suggest that administrators should treat the vulnerability as critical and patch immediately.
OpenCVE Enrichment