An unrestricted upload of file with dangerous type vulnerability in the upload file function of Galaxy Software Services Corporation Vitals ESP Forum Module through 1.3 version allows remote authenticated users to execute arbitrary system commands via a malicious file.
References
Link Providers
https://zuso.ai/advisory cve-icon cve-icon
History

Mon, 20 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 20 Oct 2025 08:00:00 +0000

Type Values Removed Values Added
Description An unrestricted upload of file with dangerous type vulnerability in the upload file function of Galaxy Software Services Corporation Vitals ESP Forum Module through 1.3 version allows remote authenticated users to execute arbitrary system commands via a malicious file.
Title Galaxy Software Services Vitals ESP Forum Module - Unrestricted Upload of File with Dangerous Type
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ZUSO ART

Published:

Updated: 2025-10-20T13:41:48.653Z

Reserved: 2025-03-28T07:11:21.680Z

Link: CVE-2025-31342

cve-icon Vulnrichment

Updated: 2025-10-20T13:37:27.339Z

cve-icon NVD

Status : Received

Published: 2025-10-20T08:15:32.570

Modified: 2025-10-20T08:15:32.570

Link: CVE-2025-31342

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.