Metrics
Affected Vendors & Products
Wed, 15 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 15 Apr 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability, which was classified as critical, was found in Vaelsys 4.1.0. This affects the function execute_DataObjectProc of the file /grid/vgrid_server.php. The manipulation of the argument xajaxargs leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | A vulnerability was identified in Vaelsys VaelsysV4 up to 5.1.0/5.4.0. Affected by this issue is the function execute_DataObjectProc of the file /grid/vgrid_server.php of the component Web interface. Such manipulation of the argument xajaxargs leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. Upgrading to version 5.1.1 and 5.4.1 can resolve this issue. It is suggested to upgrade the affected component. |
| Title | Vaelsys vgrid_server.php execute_DataObjectProc os command injection | Vaelsys VaelsysV4 Web interface vgrid_server.php execute_DataObjectProc os command injection |
| References |
| |
| Metrics |
cvssV2_0
|
cvssV2_0
|
Thu, 31 Jul 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:vaelsys:vaelsys:4.1.0:*:*:*:*:*:*:* |
Tue, 29 Jul 2025 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vaelsys
Vaelsys vaelsys |
|
| Vendors & Products |
Vaelsys
Vaelsys vaelsys |
Mon, 28 Jul 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 28 Jul 2025 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability, which was classified as critical, was found in Vaelsys 4.1.0. This affects the function execute_DataObjectProc of the file /grid/vgrid_server.php. The manipulation of the argument xajaxargs leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Vaelsys vgrid_server.php execute_DataObjectProc os command injection | |
| Weaknesses | CWE-77 CWE-78 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-04-15T07:08:25.330Z
Reserved: 2025-07-26T16:14:16.170Z
Link: CVE-2025-8259
Updated: 2025-07-28T15:58:53.568Z
Status : Modified
Published: 2025-07-28T06:15:23.837
Modified: 2026-04-15T08:16:15.760
Link: CVE-2025-8259
No data.
OpenCVE Enrichment
Updated: 2025-07-28T15:24:21Z