Vulnerability Description
SpotAuditor 5.3.1.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting excessive data in the registration name field. Attackers can enter a large string of characters (5000 bytes or more) in the name field during registration to trigger an unhandled exception that crashes the application.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nsasoft | Spotauditor | <= 5.3.1.0 |
Related Weaknesses (CWE)
References
- http://www.nsauditor.comProduct
- https://www.exploit-db.com/exploits/47494ExploitVDB Entry
- https://www.vulncheck.com/advisories/spotauditor-denial-of-service-via-registratThird Party Advisory
FAQ
What is CVE-2019-25434?
CVE-2019-25434 is a vulnerability with a CVSS score of 7.5 (HIGH). SpotAuditor 5.3.1.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting excessive data in the registration name field. Attackers can...
How severe is CVE-2019-25434?
CVE-2019-25434 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-25434?
Check the references section above for vendor advisories and patch information. Affected products include: Nsasoft Spotauditor.