CVE-2023-4491: Easy Address Book Web Server Project Easy Address Book Web Server
Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.
Buffer overflow vulnerability in Easy Address Book Web Server 1.6 version. The exploitation of this vulnerability could allow an attacker to send a very long username string to /searchbook.ghp, asking for the name via a POST request, resulting in arbitrary code execution on the remote machine.
Affected products
- Easy Address Book Web Server Project Easy Address Book Web Server: version 1.6 only
Published 2023-10-04. Last modified 2026-06-17.