CVE-2019-25552
CEWE PHOTO SHOW 6.4.3 contains a denial of service vulnerability that allows attackers to crash the application by submitting an excessively long buffer to the password field. Attackers can paste a large string of repeated characters into the password input during the upload process to trigger an application crash.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.40%
- CWE
- CWE-836
- Published
- 2026-03-21
- Last modified
- 2026-03-23
Affected products
- Cewe-Photoworld CEWE PHOTO SHOW
Weakness type
Related vulnerabilities
- CVE-2026-44736 — OpenProject: Relations API Filter Bypasses Visibility Scope, Leaking Cross-Project Work Package Subjects
- CVE-2026-9222 — Setracker2 Children's Smartwatch Ecosystem Use of password hash instead of password for authentication
- CVE-2026-40103 — Vikunja's Scoped API tokens with projects.background permission can delete project backgrounds
- CVE-2025-64471 — A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability...
- CVE-2025-62618 — ELOG file upload stored XSS
- CVE-2025-52543 — Login to the application services using only the password hash
- CVE-2025-48925 — The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do...
- CVE-2023-39546 — CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X SingleServerSafe...