vendor:
SpotOutlook
by:
Ismail Tasdelen
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: SpotOutlook
Affected Version From: 1.2.6
Affected Version To: 1.2.6
Patch Exists: NO
Related CWE: N/A
CPE: a:nsauditor:spotoutlook:1.2.6
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2020
SpotOutlook 1.2.6 – ‘Name’ Denial of Service (PoC)
SpotOutlook 1.2.6 is vulnerable to a denial of service attack when a malicious user sends a large amount of data to the 'Name' field. When the data is pasted into the 'Name' field and the 'Ok' button is clicked, the application will crash.
Mitigation:
Users should ensure that they are running the latest version of SpotOutlook and should not paste large amounts of data into the 'Name' field.