In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Missing Authorization vulnerabilities in an interactive lesson.
Start learningUpgrade kimai/kimai to version 2.58.0 or higher.
Affected versions of this package are vulnerable to Missing Authorization through insufficient authorization checks in the postMemberAction and postActivityAction API endpoints. An attacker can expand their management scope to add users or activities outside their authorized visibility by directly invoking backend API routes, bypassing frontend restrictions.