CVE-2019-25613

Easy Chat Server 3.1 contains a denial of service vulnerability that allows remote attackers to crash the application by sending oversized data in the message parameter. Attackers can establish a session via the chat.ghp endpoint and then send a POST request to body2.ghp with an excessively large message parameter value to cause the service to crash.
Configurations

Configuration 1 (hide)

cpe:2.3:a:echatserver:easy_chat_server:3.1:*:*:*:*:*:*:*

History

02 Apr 2026, 20:52

Type Values Removed Values Added
CPE cpe:2.3:a:echatserver:easy_chat_server:3.1:*:*:*:*:*:*:*
First Time Echatserver
Echatserver easy Chat Server
References () http://www.echatserver.com - () http://www.echatserver.com - Broken Link
References () http://www.echatserver.com/ecssetup.exe - () http://www.echatserver.com/ecssetup.exe - Broken Link
References () https://www.exploit-db.com/exploits/46806 - () https://www.exploit-db.com/exploits/46806 - Exploit, Third Party Advisory, VDB Entry
References () https://www.vulncheck.com/advisories/easy-chat-server-denial-of-service-via-message-parameter - () https://www.vulncheck.com/advisories/easy-chat-server-denial-of-service-via-message-parameter - Third Party Advisory
Summary
  • (es) Easy Chat Server 3.1 contiene una vulnerabilidad de denegación de servicio que permite a atacantes remotos bloquear la aplicación enviando datos de tamaño excesivo en el parámetro message. Los atacantes pueden establecer una sesión a través del endpoint chat.ghp y luego enviar una solicitud POST a body2.ghp con un valor del parámetro message excesivamente grande para causar el bloqueo del servicio.

22 Mar 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-22 14:16

Updated : 2026-04-02 20:52


NVD link : CVE-2019-25613

Mitre link : CVE-2019-25613

CVE.ORG link : CVE-2019-25613


JSON object : View

Products Affected

echatserver

  • easy_chat_server
CWE
CWE-940

Improper Verification of Source of a Communication Channel