An unrestricted upload of file with dangerous type vulnerability in the upload file function of Galaxy Software Services Corporation Vitals ESP Forum Module through 1.3 version allows remote authenticated users to execute arbitrary system commands via a malicious file.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
Link | Providers |
---|---|
https://zuso.ai/advisory |
![]() ![]() |
History
Mon, 20 Oct 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 20 Oct 2025 08:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An unrestricted upload of file with dangerous type vulnerability in the upload file function of Galaxy Software Services Corporation Vitals ESP Forum Module through 1.3 version allows remote authenticated users to execute arbitrary system commands via a malicious file. | |
Title | Galaxy Software Services Vitals ESP Forum Module - Unrestricted Upload of File with Dangerous Type | |
Weaknesses | CWE-434 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: ZUSO ART
Published:
Updated: 2025-10-20T13:41:48.653Z
Reserved: 2025-03-28T07:11:21.680Z
Link: CVE-2025-31342

Updated: 2025-10-20T13:37:27.339Z

Status : Received
Published: 2025-10-20T08:15:32.570
Modified: 2025-10-20T08:15:32.570
Link: CVE-2025-31342

No data.

No data.