Privilege Escalation Vulnerability in MaysWind ezBookkeeping Software
CVE-2024-57603

6.3MEDIUM

Key Information:

Vendor

MaysWind

Vendor
CVE Published:
12 February 2025

What is CVE-2024-57603?

A vulnerability has been identified in MaysWind ezBookkeeping version 0.7.0 that allows remote attackers to escalate privileges due to insufficient rate limiting. This flaw can be exploited by unauthorized users, granting them elevated permissions and access to restricted functionalities within the application. Implementing proper rate limiting measures is crucial to mitigate this security risk.

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.