An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.