CNNVD-202512-1003 Information

CNNVD ID

CNNVD-202512-1003

CVE-2025-14253

  • CNNVD Published: 2025-12-08

Description (Chinese)

Galaxy Software Services Vitals ESP是中国叡扬资讯(Galaxy Software Services)公司的一个用于办公的知识管理系统。 Galaxy Software Services Vitals ESP存在安全漏洞,该漏洞源于绝对路径遍历,可能导致任意文件读取。

Description (English)

Galaxy Software Services Vitals ESP is a knowledge management system for offices of the Chinese company Galaxy Software Services. There is a security loophole in Galaxy Software Services Vitals ESP, which originates from an absolute path that may lead to any document being read.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

叡扬资讯

Published

2025-12-08

Last Modified

2026-02-24

References

https://www.twcert.org.tw/en/cp-139-10543-380bd-2.html https://www.twcert.org.tw/tw/cp-132-10542-4c682-1.html

Share on: