---
id: CVE-2025-31342
title: >-
  An unrestricted upload of file with dangerous type vulnerability in the upload
  file function of Galaxy Software Services Corporation Vitals ESP Forum Module
  through 1.3 version allows remote authenticated users to execute arbitrary
  syste…
summary: >-
  An unrestricted upload of file with dangerous type vulnerability in the upload
  file function of Galaxy Software Services Corporation Vitals ESP Forum Module
  through 1.3 version allows remote authenticated users to execute arbitrary
  syste…
severity: none
cwe:
  - CWE-434
published: '2025-10-20'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-31342'
references:
  - url: 'https://zuso.ai/advisory/za-2025-15'
    label: ART@zuso.ai
tags:
  - nvd
epss: 0.00491
epssPercentile: 0.39893
ingestedAt: '2026-09-30T23:29:32.435Z'
---

## Overview

An unrestricted upload of file with dangerous type vulnerability in the upload file function of Galaxy Software Services Corporation Vitals ESP Forum Module through 1.3 version allows remote authenticated users to execute arbitrary system commands via a malicious file.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
