GHSA-j5mc-p8qg-39j7: Kimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark Manipulation
Kimai 2.56.0 contains an authenticated improper authorization / IDOR vulnerability in the favorite timesheet add and remove endpoints. A low-privileged user who knows another user’s timesheet.id can add that record to, or remove it from, the victim’s favorite/recent bookmark list. This allows cross-user manipulation of per-user favorite state without administrative privileges.
References
Code Behaviors & Features
Detect and mitigate GHSA-j5mc-p8qg-39j7 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →