CVE 9.3 CRITICAL

Galaxy Software Services Vitals ESP Forum Module – Unrestricted Upload of File with Dangerous Type_CVE-2025-31342

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H

Description

An unrestricted upload of file with dangerous type vulnerability in the upload file function of Galaxy Software Services Corporation Vitals ESP Forum Module through 1.3 version allows remote authenticated users to execute arbitrary system commands via a malicious file.

Basic Information

ID CVE-2025-31342
Source ZUSO ART
Published Oct 20, 2025 at 07:56

Affected Product

Vendor Galaxy Software Services Corporation
Product Vitals ESP
Affected Versions Galaxy Software Services Corporation Vitals ESP 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.