Easy Chat Server 3.1 contains a denial of service vulnerability that allows remote attackers to crash the application by sending oversized data in the message parameter. Attackers can establish a session via the chat.ghp endpoint and then send a POST request to body2.ghp with an excessively large message parameter value to cause the service to crash.
References
| Link | Resource |
|---|---|
| http://www.echatserver.com | Broken Link |
| http://www.echatserver.com/ecssetup.exe | Broken Link |
| https://www.exploit-db.com/exploits/46806 | Exploit Third Party Advisory VDB Entry |
| https://www.vulncheck.com/advisories/easy-chat-server-denial-of-service-via-message-parameter | Third Party Advisory |
Configurations
History
02 Apr 2026, 20:52
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:echatserver:easy_chat_server:3.1:*:*:*:*:*:*:* | |
| First Time |
Echatserver
Echatserver easy Chat Server |
|
| References | () http://www.echatserver.com - Broken Link | |
| References | () http://www.echatserver.com/ecssetup.exe - Broken Link | |
| References | () https://www.exploit-db.com/exploits/46806 - Exploit, Third Party Advisory, VDB Entry | |
| References | () https://www.vulncheck.com/advisories/easy-chat-server-denial-of-service-via-message-parameter - Third Party Advisory | |
| Summary |
|
22 Mar 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-22 14:16
Updated : 2026-04-02 20:52
NVD link : CVE-2019-25613
Mitre link : CVE-2019-25613
CVE.ORG link : CVE-2019-25613
JSON object : View
Products Affected
echatserver
- easy_chat_server
CWE
CWE-940
Improper Verification of Source of a Communication Channel
