SpotAuditor 5.3.1.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting excessive data in the registration name field. Attackers can enter a large string of characters (5000 bytes or more) in the name field during registration to trigger an unhandled exception that crashes the application.
References
| Link | Resource |
|---|---|
| http://www.nsauditor.com | Product |
| https://www.exploit-db.com/exploits/47494 | Exploit VDB Entry |
| https://www.vulncheck.com/advisories/spotauditor-denial-of-service-via-registration-name-field | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-02-20 23:16
Updated : 2026-03-05 01:05
NVD link : CVE-2019-25434
Mitre link : CVE-2019-25434
CVE.ORG link : CVE-2019-25434
JSON object : View
Products Affected
nsasoft
- spotauditor
CWE
CWE-121
Stack-based Buffer Overflow
