VYPR

X Prepay

by Gridscale

CVEs (2)

  • CVE-2025-40807Dec 9, 2025
    risk 0.00cvss epss 0.00

    A vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerable to capture-replay of authentication tokens. This could allow an authenticated but already locked-out user to establish still valid user sessions.

  • CVE-2025-40806Dec 9, 2025
    risk 0.00cvss epss 0.00

    A vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerable to user enumeration due to distinguishable responses. This could allow an unauthenticated remote attacker to determine if a user is valid or not, enabling a brute force attack with valid users.