CVE-2025-8260

LOW

Vaelsys - Broken Cryptographic Algorithm

Title source: rule

Description

A vulnerability has been found in Vaelsys 4.1.0 and classified as problematic. This vulnerability affects unknown code of the file /grid/vgrid_server.php of the component MD4 Hash Handler. The manipulation of the argument xajaxargs leads to use of weak hash. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Scores

CVSS v3 3.1
EPSS 0.0002
EPSS Percentile 5.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-327 CWE-328
Status published

Affected Products (1)

vaelsys/vaelsys

Timeline

Published Jul 28, 2025
Tracked Since Feb 18, 2026