← Πίσω στην αναζήτηση CVE

CVE-2026-80194

Kimai

Περιγραφή

Kimai before 2.64.0 contains a missing authorization vulnerability in the ProjectViewController export route (report_project_view_export). The authorization guards are attached to the sibling __invoke method rather than at the class level, so the export route inherits no authorization checks. Any authenticated user, including a plain ROLE_USER without the project_reporting permission, can download the project overview export - which returns the same dataset as the protected report - disclosing customer names, project names, currency, budget type, and aggregate totals across all customers. Actual financial figures remain protected in the export template.

CVSS 4.3EPSS 0.241%Κίνδυνος 0.44
Προβολή πηγής
Δημοσίευση
2026-08-26 05:18:26
Επηρεαζόμενες εκδόσεις
<2.64.0
Τύπος
Εφαρμογή ιστού
Τελευταία τροποποίηση
2026-08-26 13:19:24
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N