PT-2025-29895 · Scada-Lts · Scada-Lts
Nmmorette
·
Published
2025-07-17
·
Updated
2025-07-17
·
CVE-2025-7728
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Scada-LTS versions prior to 2.8.0
Description
A problematic vulnerability exists in Scada-LTS. The issue affects an unknown function within the
users.shtm file. Manipulation of the Username argument can lead to cross-site scripting (XSS). The attack can be launched remotely. The exploit has been publicly disclosed and may be used. The vendor has confirmed a fix will be included in the next release.Recommendations
Scada-LTS versions prior to 2.8.0: Upgrade to version 2.8.0 or later to resolve this issue.
Exploit
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Scada-Lts