mayswind ezBookkeeping before 2.0.0 TOTP Replay Attack
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.6epss 0.2%
probabilidad de explotación
0.2%top 86% de las CVE
explotación observada
noninguna fuente lo reporta
mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after use, allowing attackers to replay captured codes within the acceptance window. Attackers with stolen credentials can authenticate and reuse a captured passcode against multiple authorization attempts for approximately 90 seconds without detection.
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Productos afectados
mayswind · ezBookkeepingReferencias
https://github.com/mayswind/ezbookkeeping/commit/3dd6286d7a3ab0f980a6d36339b9c9c4df9467e4https://github.com/mayswind/ezbookkeeping/releases/tag/v2.0.0https://github.com/mayswind/ezbookkeeping/security/advisories/GHSA-p6qr-48g6-97q3https://www.vulncheck.com/advisories/mayswind-ezbookkeeping-before-2.0.0-totp-replay-attack