Incorrect Default Permissions
CVE-2024-57604
Summary
An issue in MaysWind ezBookkeeping allows a remote attacker to escalate privileges via the "token" component. This issue affects github.com/mayswind/ezbookkeeping versions prior to 0.8.0. This has the same fix as CVE-2024-57603.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- NONE
- HIGH
- HIGH
CWE-276 - Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
References
Advisory Timeline
- Published