Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. kimai/kimai
  4. ›
  5. GHSA-j5mc-p8qg-39j7

GHSA-j5mc-p8qg-39j7: Kimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark Manipulation

July 2, 2026

Kimai 2.56.0 contains an authenticated improper authorization / IDOR vulnerability in the favorite timesheet add and remove endpoints. A low-privileged user who knows another user’s timesheet.id can add that record to, or remove it from, the victim’s favorite/recent bookmark list. This allows cross-user manipulation of per-user favorite state without administrative privileges.

References

  • github.com/advisories/GHSA-j5mc-p8qg-39j7
  • github.com/kimai/kimai/security/advisories/GHSA-j5mc-p8qg-39j7
  • www.kimai.org/en/security/ghsa-j5mc-p8qg-39j7

Code Behaviors & Features

Detect and mitigate GHSA-j5mc-p8qg-39j7 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.57.0

Fixed versions

  • 2.57.0

Solution

Upgrade to version 2.57.0 or above.

Impact 4.3 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-639: Authorization Bypass Through User-Controlled Key
  • CWE-862: Missing Authorization

Source file

packagist/kimai/kimai/GHSA-j5mc-p8qg-39j7.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Thu, 16 Jul 2026 00:17:48 +0000.