CVE-2025-10234: Cross Site Scripting in Scada-LTS
A vulnerability was detected in Scada-LTS up to 2.7.8.1. This vulnerability affects unknown code of the file /data_point_edit.shtm of the component Data Point Edit Module. The manipulation of the argument Text Renderer properties results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-10234: Cross Site Scripting in Scada-LTS
Description
A vulnerability was detected in Scada-LTS up to 2.7.8.1. This vulnerability affects unknown code of the file /data_point_edit.shtm of the component Data Point Edit Module. The manipulation of the argument Text Renderer properties results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- VulDB
- Date Reserved
- 2025-09-10T13:53:34.904Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 68c20da512193b50d3018eb0
Added to database: 9/10/2025, 11:45:41 PM
Last updated: 9/10/2025, 11:45:41 PM
Views: 1
Related Threats
CVE-2025-10233: Path Traversal in kalcaddle kodbox
MediumCVE-2025-10232: Path Traversal in 299ko
MediumCVE-2025-10229: Open Redirect in Freshwork
MediumCVE-2025-10218: SQL Injection in lostvip-com ruoyi-go
MediumCVE-2025-10216: Race Condition in GrandNode
LowActions
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.