CVE-2018-10827

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
09/05/2018
Last modified:
12/06/2018

Description

LiteCart before 2.1.2 allows remote attackers to cause a denial of service (memory consumption) via URIs that do not exist, because public_html/logs/not_found.log grows without bound, and is loaded into memory for each request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:litecart:litecart:*:*:*:*:*:*:*:* 2.1.2 (excluding)


References to Advisories, Solutions, and Tools