Description

An unauthenticated SQL injection vulnerability exists in Kimai version 0.9.2.x via the db_restore.php endpoint. The flaw allows attackers to inject arbitrary SQL queries into the dates[] POST parameter, enabling file write via INTO OUTFILE under specific environmental conditions. This can lead to remote code execution by writing a PHP payload to the web-accessible temporary directory. The vulnerability has been confirmed in versions including 0.9.2.beta, 0.9.2.1294.beta, and 0.9.2.1306-3.

INFO

Published Date :

2025-07-31T14:56:59.144Z

Last Modified :

2025-07-31T18:52:47.787Z

Source :

VulnCheck
AFFECTED PRODUCTS

The following products are affected by CVE-2013-10033 vulnerability.

Vendors Products
Kimai
  • Kimai
Kimai Project
  • Kimai

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability