Impact
The updated description clarifies that the Entries component in Brainstorm Force SureForms versions prior to 2.12.3 does not enforce adequate limits on user-controlled form fields during processing and rendering. This flaw enables a remote attacker to submit crafted data that exhausts server resources, causing administrators to lose access to the Entries interface and triggering HTTP 500 errors.
Affected Systems
The vulnerability affects SureForms software from the vendor SureForms, specifically all releases older than version 2.12.3.
Risk and Exploitability
The EPSS score is available and indicates a very low exploitation probability, less than 1% (approximately 0.5%); the CVSS score of 7.5 classifies the vulnerability as high severity. The reported impact of exhausting server resources and producing HTTP 500 errors represents a denial‑of‑service risk. The vulnerability is listed as not included in the CISA KEV catalog. The likely attack vector is remote via web form submissions, no authentication required to trigger the resource exhaustion.
OpenCVE Enrichment