PT-2025-34136 · Scada-Lts · Scada-Lts
Marceloqz
·
Published
2025-08-20
·
Updated
2025-08-21
·
CVE-2025-9234
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Scada-LTS versions prior to 2.7.8.2
Description:
A vulnerability exists in Scada-LTS that allows for cross-site scripting (XSS). The issue is related to the manipulation of the
Alias argument within an unknown function of the maintenance events.shtm file. This attack can be executed remotely. The exploit is publicly available.Recommendations:
Update Scada-LTS to version 2.7.8.2 or later.
As a temporary workaround, sanitize the
Alias argument to prevent the injection of malicious scripts.
Restrict access to the maintenance events.shtm file to minimize the risk of exploitation.Exploit
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Scada-Lts