Vulnerabilities
Vulnerable Software
Mayswind:  >> Ezbookkeeping  Security Vulnerabilities
mayswind ezbookkeeping versions 1.2.0 and earlier contain a critical vulnerability in JSON and XML file import processing. The application fails to validate nesting depth during parsing operations, allowing authenticated attackers to trigger denial of service conditions by uploading deeply nested malicious files. This results in CPU exhaustion, service degradation, or complete service unavailability.
CVSS Score
6.5
EPSS Score
0.001
Published
2026-02-18
An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.
CVSS Score
9.8
EPSS Score
0.005
Published
2025-02-12
An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the lack of rate limiting.
CVSS Score
6.3
EPSS Score
0.0
Published
2025-02-12


Contact Us

Shodan ® - All rights reserved