Vulnerability Description
Stack-based buffer overflow vulnerability in Easy Chat Server 3.1 version. An attacker could send an excessively long username string to the register.ghp file asking for the name via a GET request resulting in arbitrary code execution on the remote machine.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Easy Chat Server Project | Easy Chat Server | 3.1 |
Related Weaknesses (CWE)
References
- https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-efs-Third Party Advisory
- https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-efs-Third Party Advisory
FAQ
What is CVE-2023-4494?
CVE-2023-4494 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Stack-based buffer overflow vulnerability in Easy Chat Server 3.1 version. An attacker could send an excessively long username string to the register.ghp file asking for the name via a GET request res...
How severe is CVE-2023-4494?
CVE-2023-4494 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-4494?
Check the references section above for vendor advisories and patch information. Affected products include: Easy Chat Server Project Easy Chat Server.