PT-2024-15756 · Unknown · Efs Easy Chat Server

Fernando.Mengali

·

Published

2024-01-18

·

Updated

2024-05-17

·

CVE-2024-0695

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions EFS Easy Chat Server version 3.1
Description A problematic issue has been found in the HTTP GET Request Handler component of the affected software. The manipulation of the USERNAME argument leads to denial of service. This issue can be exploited remotely. The vendor was contacted about this issue but did not respond.
Recommendations For EFS Easy Chat Server version 3.1, consider disabling the HTTP GET Request Handler component or restricting access to it until a fix is available. Avoid using the USERNAME argument in the affected component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Improper Resource Release

Weakness Enumeration

Related Identifiers

CVE-2024-0695

Affected Products

Efs Easy Chat Server