PT-2025-6753 · Mayswind · Mayswind Ezbookkeeping

0Xhamy

·

Published

2025-02-12

·

Updated

2025-06-06

·

CVE-2024-57604

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MaysWind ezBookkeeping version 0.7.0
Description An issue in MaysWind ezBookkeeping allows a remote attacker to escalate privileges via the token component.
Recommendations For MaysWind ezBookkeeping version 0.7.0, consider disabling the token component as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Privilege Management

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2024-57604
GHSA-MPG8-8X9C-P9GV
GO-2025-3474
OPENSUSE-SU-2025:14889-1

Affected Products

Mayswind Ezbookkeeping