CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
46.0%
Galaxy Software Services Corporation Vitals ESP is an online knowledge base management portal, it has insufficient filtering and validation during file upload. An authenticated remote attacker with general user privilege can exploit this vulnerability to upload and execute scripts onto arbitrary directories to perform arbitrary system operations or disrupt service.
Vendor | Product | Version | CPE |
---|---|---|---|
gss | vitals_enterprise_social_platform | * | cpe:2.3:a:gss:vitals_enterprise_social_platform:*:*:*:*:*:*:*:* |
[
{
"defaultStatus": "unaffected",
"product": "Vitals ESP ",
"vendor": "Galaxy Software Services",
"versions": [
{
"status": "affected",
"version": "6.1 and prior"
}
]
}
]