Easy Chat Server 3.1 contains a denial of service vulnerability that allows remote attackers to crash the application by sending oversized data in the message parameter. Attackers can establish a session via the chat.ghp endpoint and then send a POST request to body2.ghp with an excessively large message parameter value to cause the service to crash.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 22 Mar 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Easy Chat Server 3.1 contains a denial of service vulnerability that allows remote attackers to crash the application by sending oversized data in the message parameter. Attackers can establish a session via the chat.ghp endpoint and then send a POST request to body2.ghp with an excessively large message parameter value to cause the service to crash. | |
| Title | Easy Chat Server 3.1 Denial of Service via message Parameter | |
| First Time appeared |
Echatserver
Echatserver easy Chat Server |
|
| Weaknesses | CWE-940 | |
| CPEs | cpe:2.3:a:echatserver:easy_chat_server:3.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Echatserver
Echatserver easy Chat Server |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-22T13:38:46.199Z
Reserved: 2026-03-22T13:24:05.342Z
Link: CVE-2019-25613
No data.
Status : Received
Published: 2026-03-22T14:16:29.740
Modified: 2026-03-22T14:16:29.740
Link: CVE-2019-25613
No data.
OpenCVE Enrichment
No data.
Weaknesses