Kimai is a web-based multi-user time-tracking application. The permission `view_other_timesheet` performs differently for the Kimai UI and the API, thus returning unexpected data through the API. When setting the `view_other_timesheet` permission to true, on the frontend, users can only see timesheet entries for teams they are a part of. When requesting all timesheets from the API, however, all timesheet entries are returned, regardless of whether the user shares team permissions or not. This vulnerability is fixed in 2.13.0.
Cite this page
CVE-2024-29200. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2024-29200
Use CWE-1220, Kimai vendor hub and Kimai product page to widen CVE-2024-29200 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-19825, CVE-2023-53957 and CVE-2021-43515 for nearby disclosures in the same product family.