CVE-2023-37291
21.07.2023, 04:15
Galaxy Software Services Vitals ESP is vulnerable to using a hard-coded encryption key. An unauthenticated remote attacker can generate a valid token parameter and exploit this vulnerability to access system to operate processes and access data. This issue affects Vitals ESP: from 3.0.8 through 6.2.0.Enginsight
Vendor | Product | Version |
---|---|---|
gss | vitals_enterprise_social_platform | 3.0.8 ≤ 𝑥 ≤ 6.2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration