cve/2022/CVE-2022-1543.md

18 lines
823 B
Markdown
Raw Permalink Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2022-1543](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1543)
![](https://img.shields.io/static/v1?label=Product&message=erudika%2Fscoold&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3C%201.49.4%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-130%20Improper%20Handling%20of%20Length%20Parameter%20Inconsistency&color=brighgreen)
### Description
Improper handling of Length parameter in GitHub repository erudika/scoold prior to 1.49.4. When the text size is large enough the service results in a momentary outage in a production environment. That can lead to memory corruption on the server.
### POC
#### Reference
- https://huntr.dev/bounties/9889d435-3b9c-4e9d-93bc-5272e0723f9f
#### Github
No PoCs found on GitHub currently.