Back to all
2025-10-20

Galaxy Software Services Vitals ESP Forum Module - Unrestricted Upload of File with Dangerous Type

ZUSOART ID
ZA-2025-15
CVE ID
CVE-2025-31342
Vulnerability Type
CWE-434: Unrestricted Upload of File with Dangerous Type
CVSS 4.0 Base
9.3
Description

An unrestricted upload of file with dangerous type vulnerability in the upload file function of Galaxy Software Services Corporation Vitals ESP Forum Module through 1.3 version allows remote authenticated users to execute arbitrary system commands via a malicious file.

Vendor
Galaxy Software Services Corporation
Product
Category
Version affected
Vitals ESP Forum Module
Through 1.3
Mitigations

Contact Galaxy Software Services Corporation for version updates.

Release date
2025-10-20
Credit

Jian You Chen (Jeremy Chen) of ZUSO ART