CVE-2025-31342

An unrestricted upload of file with dangerous type vulnerability in the upload file function of Galaxy Software Services Corporation Vitals ESP Forum Module through 1.3 version allows remote authenticated users to execute arbitrary system commands via a malicious file.
CVSS

No CVSS.

References
Link Resource
https://zuso.ai/advisory
Configurations

No configuration.

History

20 Oct 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-20 08:15

Updated : 2025-10-21 19:31


NVD link : CVE-2025-31342

Mitre link : CVE-2025-31342

CVE.ORG link : CVE-2025-31342


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type