CVE-2025-65519: Medium severity MaysWind ezBookkeeping vulnerability
mayswind ezbookkeeping versions 1.2.0 and earlier contain a critical vulnerability in JSON and XML file import processing. The application fails to validate nesting depth during parsing operations, allowing authenticated attackers to trigger denial of service conditions by uploading deeply nested malicious files. This results in CPU exhaustion, service degradation, or complete service unavailability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-65519?
CVE-2025-65519 is classified as a critical vulnerability due to its potential to cause denial of service conditions.
How do I fix CVE-2025-65519?
To fix CVE-2025-65519, update Mayswind ezbookkeeping to version 1.2.1 or later which addresses the vulnerability.
Who is affected by CVE-2025-65519?
CVE-2025-65519 affects users of Mayswind ezbookkeeping versions 1.2.0 and earlier.
What type of attack does CVE-2025-65519 facilitate?
CVE-2025-65519 facilitates a denial of service attack through deep nesting in JSON and XML file imports.
Is authentication required to exploit CVE-2025-65519?
Yes, an attacker must be authenticated to exploit the CVE-2025-65519 vulnerability.