CVE-2025-9144

A weakness has been identified in Scada-LTS 2.7.8.1. This vulnerability affects unknown code of the file publisher_edit.shtm. This manipulation of the argument Name causes cross site scripting. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited.
References
Link Resource
https://karinagante.github.io/cve-2025-9144/ Exploit Third Party Advisory
https://karinagante.github.io/cve-2025-9144/#proof-of-concept-poc Exploit
https://vuldb.com/?ctiid.320522 Permissions Required VDB Entry
https://vuldb.com/?id.320522 Third Party Advisory VDB Entry
https://vuldb.com/?submit.628445 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:scada-lts:scada-lts:2.7.8.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-08-19 15:15

Updated : 2025-09-11 14:48


NVD link : CVE-2025-9144

Mitre link : CVE-2025-9144

CVE.ORG link : CVE-2025-9144


JSON object : View

Products Affected

scada-lts

  • scada-lts
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')