Galaxy Software Services Vitals ESP - Arbitrary File Upload
CVE-2023-41357

8.8HIGH

Key Information:

Vendor
CVE Published:
3 November 2023

What is CVE-2023-41357?

The Vitals ESP portal by Galaxy Software Services Corporation suffers from a flaw in its file upload functionality, allowing attackers with authenticated user access to bypass filtering mechanisms. This exploit enables unauthorized script uploads to arbitrary directories, potentially leading to arbitrary code execution and service disruption. Security measures are essential to prevent exploitation that could compromise system integrity and user data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Vitals ESP 6.1 and prior

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.