CVE-2025-8261 | Vaelsys VaelsysV4 4.1.0 User Creation /grid/vgrid_server.php improper authorization
A vulnerability was found in Vaelsys VaelsysV4 4.1.0. It has been declared as critical. This vulnerability affects unknown code of the file /grid/vgrid_server.php of the component User Creation Handler. Executing a manipulation can lead to improper authorization.
This vulnerability appears as CVE-2025-8261. The attack may be performed from remote. In addition, an exploit is available.
The real existence of this vulnerability is still doubted at the moment.
The vendor explains: "Based on Vaelsys' analysis, the reported behavior does not allow actions beyond those already permitted to authenticated administrative users, and no change in system configuration or operational practices is necessary."