CVE-2019-25618

MEDIUM

AdminExpress 1.2.5 Denial of Service via System Compare

Title source: cna

Description

AdminExpress 1.2.5 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input through the System Compare feature. Attackers can paste a large buffer of characters into the Folder Path field and trigger the comparison function to cause the application to become unresponsive or crash.

Exploits (1)

exploitdb WORKING POC
by Mücahit İsmail Aktaş · pythondoswindows
https://www.exploit-db.com/exploits/46711

Scores

CVSS v3 6.2
EPSS 0.0001
EPSS Percentile 3.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-73
Status published
Products (1)
Admin-Express/AdminExpress 1.2.5.485
Published Mar 22, 2026
Tracked Since Mar 22, 2026