CVE-2019-25618
MEDIUMAdminExpress 1.2.5 Denial of Service via System Compare
Title source: cnaDescription
AdminExpress 1.2.5 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input through the System Compare feature. Attackers can paste a large buffer of characters into the Folder Path field and trigger the comparison function to cause the application to become unresponsive or crash.
Exploits (1)
exploitdb
WORKING POC
by Mücahit İsmail Aktaş · pythondoswindows
https://www.exploit-db.com/exploits/46711
Scores
CVSS v3
6.2
EPSS
0.0001
EPSS Percentile
3.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-73
Status
published
Products (1)
Admin-Express/AdminExpress
1.2.5.485
Published
Mar 22, 2026
Tracked Since
Mar 22, 2026