PT-2025-29895 · Scada-Lts · Scada-Lts

Nmmorette

·

Published

2025-07-17

·

Updated

2025-07-17

·

CVE-2025-7728

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Scada-LTS versions prior to 2.8.0
Description A problematic vulnerability exists in Scada-LTS. The issue affects an unknown function within the users.shtm file. Manipulation of the Username argument can lead to cross-site scripting (XSS). The attack can be launched remotely. The exploit has been publicly disclosed and may be used. The vendor has confirmed a fix will be included in the next release.
Recommendations Scada-LTS versions prior to 2.8.0: Upgrade to version 2.8.0 or later to resolve this issue.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2025-15296
CVE-2025-7728

Affected Products

Scada-Lts