Description
One Search 1.1.0.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting excessively long input strings to the search functionality. Attackers can paste a buffer of 950 or more characters into the search bar to trigger an unhandled exception that crashes the application.
Problem types
Incorrect Parsing of Numbers with Different Radices
Product status
Credits
0xB9
References
www.exploit-db.com/exploits/46195 (ExploitDB-46195)
www.microsoft.com/store/productId/9PMR5QNS5LTL (Product Reference)
www.vulncheck.com/advisories/one-search-denial-of-service (VulnCheck Advisory: One Search 1.1.0.0 Denial of Service)