PT-2024-31855 · Kimai · Kimai

Deepcove

·

Published

2024-05-07

·

Updated

2025-10-10

·

CVE-2024-4596

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kimai versions up to 2.15.0
Description A vulnerability was found in the Session Handler component of Kimai, where the manipulation of the PHPSESSIONID argument leads to information disclosure. The attack can be launched remotely, with a rather high complexity and difficult exploitation.
Recommendations For Kimai versions up to 2.15.0, upgrade to version 2.16.0 to address this issue. As a temporary workaround, consider restricting access to the Session Handler component until the upgrade is applied.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-4596
GHSA-6F3V-2R2J-2RPR

Affected Products

Kimai