CVE-2019-25434

SpotAuditor 5.3.1.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting excessive data in the registration name field. Attackers can enter a large string of characters (5000 bytes or more) in the name field during registration to trigger an unhandled exception that crashes the application.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nsasoft:spotauditor:*:*:*:*:*:*:*:*

History

05 Mar 2026, 01:05

Type Values Removed Values Added
Summary
  • (es) SpotAuditor 5.3.1.0 contiene una vulnerabilidad de denegación de servicio que permite a atacantes no autenticados provocar la caída de la aplicación al enviar datos excesivos en el campo de nombre de registro. Los atacantes pueden introducir una cadena grande de caracteres (5000 bytes o más) en el campo de nombre durante el registro para activar una excepción no controlada que provoca la caída de la aplicación.
CPE cpe:2.3:a:nsasoft:spotauditor:*:*:*:*:*:*:*:*
First Time Nsasoft
Nsasoft spotauditor
References () http://www.nsauditor.com - () http://www.nsauditor.com - Product
References () https://www.exploit-db.com/exploits/47494 - () https://www.exploit-db.com/exploits/47494 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/spotauditor-denial-of-service-via-registration-name-field - () https://www.vulncheck.com/advisories/spotauditor-denial-of-service-via-registration-name-field - Third Party Advisory

20 Feb 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-20 23:16

Updated : 2026-03-05 01:05


NVD link : CVE-2019-25434

Mitre link : CVE-2019-25434

CVE.ORG link : CVE-2019-25434


JSON object : View

Products Affected

nsasoft

  • spotauditor
CWE
CWE-121

Stack-based Buffer Overflow