In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Authorization Bypass Through User-Controlled Key vulnerabilities in an interactive lesson.
Start learningUpgrade kimai/kimai to version 2.57.0 or higher.
Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key via the rate editing process for projects, customers, and activities. An attacker can modify billing-related rate configurations outside their authorized scope by combining an authorized parent object ID with the rate ID of an unauthorized parent object in the relevant endpoints.