← voltar
CVE-2019-25613

Easy Chat Server 3.1 Denial of Service via message Parameter

CVSS 8.7 HIGHEPSS 0.5%CWE-940
Easy Chat Server 3.1 contains a denial of service vulnerability that allows remote attackers to crash the application by sending oversized data in the message parameter. Attackers can establish a session via the chat.ghp endpoint and then send a POST request to body2.ghp with an excessively large message parameter value to cause the service to crash.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Produtos afetados
Echatserver · Easy Chat

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →