CVE-2023-41357

Galaxy Software Services Corporation Vitals ESP is an online knowledge base management portal, it has insufficient filtering and validation during file upload. An authenticated remote attacker with general user privilege can exploit this vulnerability to upload and execute scripts onto arbitrary directories to perform arbitrary system operations or disrupt service.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gss:vitals_enterprise_social_platform:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:21

Type Values Removed Values Added
References () https://www.twcert.org.tw/tw/cp-132-7508-6d1ef-1.html - Third Party Advisory () https://www.twcert.org.tw/tw/cp-132-7508-6d1ef-1.html - Third Party Advisory

13 Nov 2023, 19:54

Type Values Removed Values Added
First Time Gss
Gss vitals Enterprise Social Platform
References (MISC) https://www.twcert.org.tw/tw/cp-132-7508-6d1ef-1.html - (MISC) https://www.twcert.org.tw/tw/cp-132-7508-6d1ef-1.html - Third Party Advisory
CPE cpe:2.3:a:gss:vitals_enterprise_social_platform:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-434

03 Nov 2023, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-03 07:15

Updated : 2024-11-21 08:21


NVD link : CVE-2023-41357

Mitre link : CVE-2023-41357

CVE.ORG link : CVE-2023-41357


JSON object : View

Products Affected

gss

  • vitals_enterprise_social_platform
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type