CVE-2025-9144
LOWScada-LTS 2.7.8.1 - Cross-Site Scripting via publisher_edit.shtm Name Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-9144. PoCs published by KarinaGante.
AI-analyzed exploit summary The repository contains a detailed technical writeup for CVE-2025-9144, focusing on a stored XSS vulnerability via SVG file upload bypass in NovoSGA. It includes PoC steps, payload examples, and impact analysis, demonstrating a clear understanding of the vulnerability mechanics.
Description
A weakness has been identified in Scada-LTS 2.7.8.1. This vulnerability affects unknown code of the file publisher_edit.shtm. This manipulation of the argument Name causes cross site scripting. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited.
Exploits (1)
The repository contains a detailed technical writeup for CVE-2025-9144, focusing on a stored XSS vulnerability via SVG file upload bypass in NovoSGA. It includes PoC steps, payload examples, and impact analysis, demonstrating a clear understanding of the vulnerability mechanics.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N