An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://github.com/mayswind/ezbookkeeping/issues/33 | exploit issue tracking third party advisory |
https://hkohi.ca/vulnerability/2 | exploit third party advisory |