The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adequate limits on user-controlled form fields or submitted content during processing and rendering, which allows a remote attacker to exhaust server resources, prevent administrators from accessing the Entries interface, and trigger HTTP 500 errors via crafted form submissions.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-18 16:17
Updated : 2026-09-03 17:45
NVD link : CVE-2026-19500
Mitre link : CVE-2026-19500
CVE.ORG link : CVE-2026-19500
JSON object : View
Products Affected
No product.
CWE
CWE-400
Uncontrolled Resource Consumption
