CVE-2018-25221

Severity CVSS v4.0:
CRITICAL
Type:
CWE-787 Out-of-bounds Write
Publication date:
28/03/2026
Last modified:
02/04/2026

Description

EChat Server 3.1 contains a buffer overflow vulnerability in the chat.ghp endpoint that allows remote attackers to execute arbitrary code by supplying an oversized username parameter. Attackers can send a GET request to chat.ghp with a malicious username value containing shellcode and ROP gadgets to achieve code execution in the application context.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:echatserver:easy_chat_server:*:*:*:*:*:*:*:* 3.1 (including)