Galaxy Software Services Vitals ESP is vulnerable to...
Critical severity
Unreviewed
Published
Jul 21, 2023
to the GitHub Advisory Database
•
Updated Oct 14, 2024
Description
Published by the National Vulnerability Database
Jul 21, 2023
Published to the GitHub Advisory Database
Jul 21, 2023
Last updated
Oct 14, 2024
Galaxy Software Services Vitals ESP is vulnerable to using a hard-coded encryption key. An unauthenticated remote attacker can generate a valid token parameter and exploit this vulnerability to access system to operate processes and access data.
This issue affects Vitals ESP: from 3.0.8 through 6.2.0.
References