GHSA-j95g-6g2h-3f33HighCVSS 6.8

mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after use, allowing...

Published
September 20, 2026
Last Modified
September 20, 2026

🔗 CVE IDs covered (1)

📋 Description

mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after use, allowing attackers to replay captured codes within the acceptance window. Attackers with stolen credentials can authenticate and reuse a captured passcode against multiple authorization attempts for approximately 90 seconds without detection.

🔗 References (6)