mayswind ezBookkeeping 2.0.0 之前的版本存在安全缺陷:TOTP(基于时间的一次性密码)在使用后未被正确失效,导致攻击者可以在接受时间窗口内重放已捕获的验证码。若攻击者窃取了合法凭证,便可以在大约90秒内,将捕获的验证码多次用于身份验证请求,从而绕过授权控制,且该行为不会被检测到。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mayswind | ezBookkeeping | 0 ~ 2.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet