Metrics
Affected Vendors & Products
Wed, 15 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 15 Apr 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in Vaelsys 4.1.0 and classified as problematic. This vulnerability affects unknown code of the file /grid/vgrid_server.php of the component MD4 Hash Handler. The manipulation of the argument xajaxargs leads to use of weak hash. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | A security flaw has been discovered in Vaelsys VaelsysV4 up to 5.1.0/5.4.0. This affects an unknown part of the file /grid/vgrid_server.php of the component Web interface. Performing a manipulation of the argument xajaxargs results in use of weak hash. The attack is possible to be carried out remotely. The complexity of an attack is rather high. It is indicated that the exploitability is difficult. The exploit has been released to the public and may be used for attacks. Upgrading to version 5.1.1 and 5.4.1 is able to mitigate this issue. Upgrading the affected component is recommended. |
| Title | Vaelsys MD4 Hash vgrid_server.php weak hash | Vaelsys VaelsysV4 Web interface vgrid_server.php weak hash |
| References |
| |
| Metrics |
cvssV2_0
|
cvssV2_0
|
Thu, 31 Jul 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:vaelsys:vaelsys:4.1.0:*:*:*:*:*:*:* |
Tue, 29 Jul 2025 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vaelsys
Vaelsys vaelsys |
|
| Vendors & Products |
Vaelsys
Vaelsys vaelsys |
Mon, 28 Jul 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 28 Jul 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in Vaelsys 4.1.0 and classified as problematic. This vulnerability affects unknown code of the file /grid/vgrid_server.php of the component MD4 Hash Handler. The manipulation of the argument xajaxargs leads to use of weak hash. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Vaelsys MD4 Hash vgrid_server.php weak hash | |
| Weaknesses | CWE-327 CWE-328 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-04-15T07:02:44.090Z
Reserved: 2025-07-26T16:14:24.601Z
Link: CVE-2025-8260
Updated: 2025-07-28T15:57:59.502Z
Status : Modified
Published: 2025-07-28T06:15:25.620
Modified: 2026-04-15T08:16:16.073
Link: CVE-2025-8260
No data.
OpenCVE Enrichment
Updated: 2025-07-28T15:24:22Z