kimai/kimai is vulnerable to Information Disclosure
39
Low Risk
The project view reporting export route places its authorization attributes on the report method instead of the controller class, so the export route inherits no permission check. Any authenticated user, including a plain role without project_reporting, can call the export and download the same project overview dataset that the report itself returns 403 for. The exposed data spans customer names, project names, currency, budget type, and aggregate totals across all customers. The fix moves the permission checks to the controller class so the report and its export share the same guards.
You are affected if you are using a version that falls within the vulnerable range.
kimai/kimai is vulnerable to Information Disclosure in versions 0.0.1 - 2.63.0.
Upgrade the kimai/kimai library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant