CVE-2017-9543

HIGH

EFS Software Easy Chat Server <3.1 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-9543. PoCs published by Aitezaz Mohsin.

AI-analyzed exploit summary This exploit demonstrates a pre-authentication remote password reset vulnerability in Easy Chat Server by sending a crafted HTTP POST request to the registration endpoint. It allows an attacker to change any user's password without authentication.

Description

register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to reset arbitrary passwords via a crafted POST request to registresult.htm.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Aitezaz Mohsin · pythonwebappswindows
https://www.exploit-db.com/exploits/42154

This exploit demonstrates a pre-authentication remote password reset vulnerability in Easy Chat Server by sending a crafted HTTP POST request to the registration endpoint. It allows an attacker to change any user's password without authentication.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Easy Chat Server v2.0 to v3.1
No auth needed
Prerequisites: Network access to the target server · Valid username to reset
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/42154/

Scores

CVSS v3 7.5
EPSS 0.0133
EPSS Percentile 67.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-640
Status published
Products (1)
echatserver/easy_chat_server 2.0 - 3.1
Published Jun 12, 2017
Tracked Since Feb 18, 2026