Denial of Service Vulnerability in Mayswind EZBookkeeping
CVE-2025-65519

6.5MEDIUM

Key Information:

Vendor

Mayswind

Vendor
CVE Published:
18 February 2026

What is CVE-2025-65519?

Mayswind EZBookkeeping versions up to 1.2.0 are exposed to a Denial of Service vulnerability through inadequate validation of nesting depth during JSON and XML file imports. This oversight can be exploited by authenticated attackers who upload maliciously crafted files. The vulnerability leads to excessive CPU consumption, resulting in service degradation or total unavailability, posing significant risks to users and their operations.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.