Buffer Overflow Vulnerability in CEWE Photoshow by CEWE
CVE-2018-25294
Key Information:
- Vendor
Cewe-photoworld
- Status
- Vendor
- CVE Published:
- 26 April 2026
Badges
What is CVE-2018-25294?
A buffer overflow vulnerability exists in CEWE Photoshow version 6.3.4, specifically within the login dialog. This flaw allows an attacker to submit oversized input by injecting 4000 bytes of data into the email address and password fields. The result is a denial of service condition, potentially crashing the application and interrupting service for users. Organizations utilizing CEWE Photoshow should review their current versions and implement necessary patches to mitigate the risks associated with this vulnerability.
Affected Version(s)
CEWE Photoshow 6.3.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
