CyberRota Analysis
AI-GeneratedKimai versions prior to 2.53.0 are susceptible to an open redirect vulnerability in the SAML authentication success handler, allowing attackers with IdP access to manipulate unvalidated RelayState POST parameters. This could lead to the redirection of authenticated users to malicious URLs, posing a risk of credential theft or phishing attacks. Organizations utilizing Kimai for SAML authentication should prioritize addressing this vulnerability to safeguard user credentials and prevent potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Kimai before 2.53.0 contains an open redirect vulnerability in the SAML authentication success handler that accepts unvalidated RelayState POST parameters as redirect destinations. Attackers with IdP access can supply malicious RelayState values to redirect authenticated users to attacker-controlled URLs for credential theft or phishing attacks.