Protection Mechanism Failure in kimai2 - #VU128253
Published: April 28, 2026
kimai2
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient implementation of security measures in the config() Twig function within invoice/export templates. A remote user can bypass implemented security restrictions and gain access to sensitive information on the system.