Description
aSc TimeTables 2020.11.4 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the Subject title field with a large buffer. Attackers can generate a 1000-character buffer and paste it into the Subject title to trigger an application crash and potential instability.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Ismael Nava
References
www.exploit-db.com/exploits/48133 (ExploitDB-48133)
www.asctimetables.com/ (Vendor Homepage)
www.vulncheck.com/...sories/asc-timetables-denial-of-service (VulnCheck Advisory: aSc TimeTables 2020.11.4 - Denial of Service)