CVE-2013-10033

An unauthenticated SQL injection vulnerability exists in Kimai version 0.9.2.x via the db_restore.php endpoint. The flaw allows attackers to inject arbitrary SQL queries into the dates[] POST parameter, enabling file write via INTO OUTFILE under specific environmental conditions. This can lead to remote code execution by writing a PHP payload to the web-accessible temporary directory. The vulnerability has been confirmed in versions including 0.9.2.beta, 0.9.2.1294.beta, and 0.9.2.1306-3.
CVSS

No CVSS.

Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de inyección SQL no autenticada en la versión 0.9.2.x de Kimai a través del endpoint db_restore.php. Esta falla permite a los atacantes inyectar consultas SQL arbitrarias en el parámetro POST «dates[]», lo que permite la escritura de archivos mediante INTO OUTFILE en condiciones específicas. Esto puede provocar la ejecución remota de código mediante la escritura de un payload PHP en el directorio temporal accesible desde la web. La vulnerabilidad se ha confirmado en versiones como 0.9.2.beta, 0.9.2.1294.beta y 0.9.2.1306-3.

31 Jul 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-31 15:15

Updated : 2026-06-16 23:50


NVD link : CVE-2013-10033

Mitre link : CVE-2013-10033

CVE.ORG link : CVE-2013-10033


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')