CVE-2024-57604
Critical
MaysWind ezBookkeeping has Improper Privilege Management in github.com/mayswind/ezbookkeeping
MaysWind ezBookkeeping has Improper Privilege Management in github.com/mayswind/ezbookkeeping
Exploit probability
0.7%
Published
March 3, 2025
Required by
Not available
Last source change
March 3, 2026
02 / AFFECTED SOFTWARE
Affected packages
2 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2024-57604
View original source
An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.
Open Source Vulnerabilities
GO-2025-3474
View original source
MaysWind ezBookkeeping has Improper Privilege Management in github.com/mayswind/ezbookkeeping
Open Source Vulnerabilities
GHSA-mpg8-8x9c-p9gv
View original source
An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.
05 / REFERENCES
Further evidence
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/57xxx/CVE-2024-57604.json
- https://github.com/mayswind/ezbookkeeping/issues/33
- https://hkohi.ca/vulnerability/2
- https://nvd.nist.gov/vuln/detail/CVE-2024-57604
- https://github.com/advisories/GHSA-mpg8-8x9c-p9gv
- https://github.com/mayswind/ezbookkeeping