vendor:
iDailyDiary
by:
Ismael Nava
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: iDailyDiary
Affected Version From: 4.30
Affected Version To: 4.30
Patch Exists: NO
Related CWE: N/A
CPE: a:splinterware:i_daily_diary:4.30
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Home x64
2021
iDailyDiary 4.30 – Denial of Service (PoC)
iDailyDiary 4.30 is vulnerable to a Denial of Service attack when a maliciously crafted .txt file is created and its content is pasted in the field below 'Default diary tab name when creating new tabs' in the 'Preferences' tab of the program. This causes the program to crash.
Mitigation:
Ensure that user input is properly validated and sanitized before being used.