CVE-2023-4491: Easy Address Book Web Server Project Easy Address Book Web Server

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

Buffer overflow vulnerability in Easy Address Book Web Server 1.6 version. The exploitation of this vulnerability could allow an attacker to send a very long username string to /searchbook.ghp, asking for the name via a POST request, resulting in arbitrary code execution on the remote machine.

Affected products

Published 2023-10-04. Last modified 2026-06-17.