go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Galaxy Software Services Corporation. Vitals ESP - Arbitrary Path File Reading

TVN ID TVN-202211010
CVE ID CVE-2022-46309
CVSS 6.5 (Medium)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected Products Galaxy Software Services Corporation. Vitals ESP 3.0.8 ~ 6.2.0
Description Vitals ESP upload function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to access arbitrary system files.
Solution Contact tech support from Galaxy Software Services Corporation.
Credit Mico Kao (DEVCORE)
Public Date 2022-12-12
Top