vendor:
InduSoft Web Studio
by:
chuyreds
7.5
CVSS
HIGH
Denial of Service (DoS) Local
400
CWE
Product Name: InduSoft Web Studio
Affected Version From: 8.1 SP1
Affected Version To: 8.1 SP1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10 Pro x64 es
2019
InduSoft Web Studio 8.1 SP1 – “Atributos” Denial of Service (PoC)
The exploit allows an attacker to cause a denial of service (DoS) condition on InduSoft Web Studio 8.1 SP1. By pasting a large buffer of characters into the "No Redibujar"/"Deshabilitados" field, the application crashes, rendering it unavailable. This can be achieved by running the provided Python code or manually copying the content of the provided text file into the application.
Mitigation:
There is no known mitigation for this vulnerability.