CVE-2024-57604: Critical severity mayswind ezbookkeeping vulnerability
Published Feb 12, 2025
·Updated
An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.
Affected Software
3 affected components
MaysWind ezBookkeeping
go/github.com/mayswind/ezbookkeeping<=0.7.0
MaysWind ezBookkeeping=0.7.0
Event History
Feb 12, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Feb 13, 2025
Advisory Published
via GitHub·12:33 AM
Data Sourced
via GitHub·12:33 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-57604?
CVE-2024-57604 has been classified as a critical vulnerability due to its potential to allow remote privilege escalation.
2
How do I fix CVE-2024-57604?
To fix CVE-2024-57604, update MaysWind ezBookkeeping to the latest version beyond 0.7.0 to eliminate the vulnerability.
3
Who is affected by CVE-2024-57604?
CVE-2024-57604 affects users of MaysWind ezBookkeeping version 0.7.0.
4
What type of vulnerability is CVE-2024-57604?
CVE-2024-57604 is a privilege escalation vulnerability that can be exploited remotely.
5
What are the implications of CVE-2024-57604?
Exploiting CVE-2024-57604 could allow an attacker to gain unauthorized access to sensitive functions within the application.