Kimai locked its project report behind a permission check and left the export route beside it open. Any logged-in user could download customer names, project names, and budget metadata across every customer. Advisory GHSA-pvc4-crg3-gj44, patched in 2.64.0.
Security researcher focused on web application vulnerabilities, exploit development,
and responsible disclosure. Currently seeking internship opportunities in offensive security.