PT-2024-31855 · Kimai · Kimai
Deepcove
·
Published
2024-05-07
·
Updated
2025-10-10
·
CVE-2024-4596
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Kimai versions up to 2.15.0
Description
A vulnerability was found in the Session Handler component of Kimai, where the manipulation of the
PHPSESSIONID argument leads to information disclosure. The attack can be launched remotely, with a rather high complexity and difficult exploitation.Recommendations
For Kimai versions up to 2.15.0, upgrade to version 2.16.0 to address this issue. As a temporary workaround, consider restricting access to the Session Handler component until the upgrade is applied.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kimai