Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-41357

Опубликовано: 03 нояб. 2023
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

Galaxy Software Services Corporation Vitals ESP is an online knowledge base management portal, it has insufficient filtering and validation during file upload. An authenticated remote attacker with general user privilege can exploit this vulnerability to upload and execute scripts onto arbitrary directories to perform arbitrary system operations or disrupt service.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gss:vitals_enterprise_social_platform:*:*:*:*:*:*:*:*
Версия до 6.1 (включая)

EPSS

Процентиль: 52%
0.00293
Низкий

8.8 High

CVSS3

Дефекты

CWE-434
CWE-434

Связанные уязвимости

CVSS3: 8.8
github
больше 2 лет назад

Galaxy Software Services Corporation Vitals ESP is an online knowledge base management portal, it has insufficient filtering and validation during file upload. An authenticated remote attacker with general user privilege can exploit this vulnerability to upload and execute scripts onto arbitrary directories to perform arbitrary system operations or disrupt service.

EPSS

Процентиль: 52%
0.00293
Низкий

8.8 High

CVSS3

Дефекты

CWE-434
CWE-434