Prepared links could change your favorites and dashboard layout
Affected versions
- Kimai versions < 2.66.0 are affected by this security issue
- The issue has been fixed in Kimai 2.66.0
- Severity: Low
- A CVE ID is requested, pending assignment
Description
Some Kimai pages changed settings when they were opened, without checking that the request came from Kimai itself. If someone got you to follow a prepared link while you’re signed in, that link could change your favorite time records or your dashboard layout.
- The impact is limited to your own settings. Nothing is disclosed or deleted, no permissions are changed, and you can correct everything in the interface.
- Affected were the favorite time records and the dashboard layout of the signed-in user. No special role or permission was involved — the change always happened in the context of your own account.
- Because Kimai’s session cookies are restricted to top-level navigation, you have to follow the link yourself. An embedded image or a background request on another site isn’t enough.
Solution
The affected actions no longer respond to a plain page request. Adding and removing a favorite time record, adding a dashboard widget, resetting the dashboard, and deleting a user role, an invoice template, or an invoice document moved to the API and accept only requests that change data on purpose.
Users should update to 2.66.0 or newer.
Credits
- Reported by: skeletonsec
- Patched by: kevinpapst
Kimai