Impact
ezBookkeeping versions 1.2.0 up to the release before 2.0.1 contain a privilege escalation flaw that allows an actor holding any API token to obtain a full 30‑day normal session token by calling the /api/v1/tokens/refresh.json endpoint. The handler does not verify the type of the incoming token, so short‑lived or IP‑restricted API tokens can be upgraded to session tokens that bypass token expiry and allowlists. The resulting session token grants broader application access, enabling an attacker to modify or disclose bookkeeping data.
Affected Systems
This vulnerability affects installations of the mayswind ezBookkeeping application. Any deployment running a version earlier than 2.0.1, including 1.2.0 and subsequent releases, is vulnerable. No other products are affected.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate severity. No EPSS score is available, so the probability of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw remotely by sending an authenticated API request to the token refresh endpoint; the absence of token‑type validation makes the attack straightforward. The possession of a new session token elevates the attacker’s privileges, potentially allowing unauthorised modification or disclosure of bookkeeping data.
OpenCVE Enrichment