CVE-2025-31342
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-10-20
Last updated on: 2025-10-21
Assigner: ZUSO Advanced Research Team (ZUSO ART)
Description
Description
An unrestricted upload of file with dangerous type vulnerability in the upload file function of Galaxy Software Services Corporation Vitals ESP Forum Module through 1.3 version allows remote authenticated users to execute arbitrary system commands via a malicious file.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| galaxy_software_services_corporation | vitals_esp_forum_module | 1.3 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-434 | The product allows the upload or transfer of dangerous file types that are automatically processed within its environment. |