CVE-2019-25613 Details
Description
Easy Chat Server 3.1 contains a denial of service vulnerability that allows remote attackers to crash the application by sending oversized data in the message parameter. Attackers can establish a session via the chat.ghp endpoint and then send a POST request to body2.ghp with an excessively large message parameter value to cause the service to crash.
A denial-of-service vulnerability has been identified in Easy Chat Server version 3.1. This issue allows remote attackers to crash the application by sending oversized data through the message parameter. Exploitation involves establishing a session via the chat.ghp endpoint and then sending a POST request to body2.ghp with an excessively large message value, causing the service to crash.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.exploit-db.com/exploits/46806 | [email protected] | ExploitThird Party AdvisoryVDB Entry |
| https://www.vulncheck.com/advisories/easy-chat-server-denial-of-service-via-message-parameter | [email protected] | Third Party Advisory |
| http://www.echatserver.com | [email protected] | Broken Link |
| http://www.echatserver.com/ecssetup.exe | [email protected] | Broken Link |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-940 | Improper Verification of Source of a Communication Channel | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| echatserver easy chat server | 3.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 2, 2026 | Initial Analysis | [email protected] |
| Mar 22, 2026 | New CVE Received | [email protected] |