云虫漏洞库

CVE-2026-80198 - Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates, allowing administrators to access arbitrary configuration keys. Attackers with admin privileges can upload malicious templates to exfiltrate server-wide secrets including LDAP bind passwords and SAML private keys into invoice or export documents accessible to lower-privileged users. - 漏洞详情

漏洞编号:CVE-2026-80198

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-80198

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-693

发布/更新时间:2026-08-26 / 2026-08-28

漏洞描述

Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates, allowing administrators to access arbitrary configuration keys. Attackers with admin privileges can upload malicious templates to exfiltrate server-wide secrets including LDAP bind passwords and SAML private keys into invoice or export documents accessible to lower-privileged users.

相关链接

相关漏洞

« 返回首页