Scada-LTS usersProfiles.shtm cross site scripting

CVE Details

Basic Information

Title Scada-LTS usersProfiles.shtm cross site scripting
Type cve
Published 2025-07-17T02:02:05.740Z
Modified 2025-07-17T02:10:25.777Z

Product Information

Vendor n/a
Product Scada-LTS
Version 2.7.8.0

CVSS Information

Base Score 5.1 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P

AI Analysis

AI Description A cross-site scripting (XSS) vulnerability was discovered in Scada-LTS versions up to 2.7.8.1. This issue affects the usersProfiles.shtm file and can be exploited remotely by manipulating the Username argument. The vendor has acknowledged the issue and plans to fix it in the upcoming release 2.8.0.
AI Severity Medium
AI Vendor Scada-LTS Project
AI Product Scada-LTS
AI Version 2.7.8.0, 2.7.8.1

Affected Products

  • n/a Scada-LTS 2.7.8.0
  • n/a Scada-LTS 2.7.8.1

Additional Information

CWE List CWE-79, CWE-94
Source VulDB

Description

A vulnerability classified as problematic was found in Scada-LTS up to 2.7.8.1. Affected by this vulnerability is an unknown functionality of the file usersProfiles.shtm. The manipulation of the argument Username leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this issue and confirmed that it will be fixed in the upcoming release 2.8.0.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.