vendor:
Easy Chat Server
by:
Miguel Mendez Z
7.5
CVSS
HIGH
Denial of Service (DoS)
400
CWE
Product Name: Easy Chat Server
Affected Version From: 3.1
Affected Version To: 3.1
Patch Exists: YES
Related CWE: N/A
CPE: a:echatserver:easy_chat_server
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2019
Easy Chat Server Version 3.1 – (DOS)
A denial of service vulnerability exists in Easy Chat Server Version 3.1 due to improper validation of user-supplied input. An attacker can send a specially crafted HTTP request with an overly long 'message' parameter to crash the application.
Mitigation:
Upgrade to the latest version of Easy Chat Server.