CVE-2025-9145
LOWScada-LTS 2.7.8.1 - XSS
Title source: llmDescription
A security vulnerability has been detected in Scada-LTS 2.7.8.1. This issue affects some unknown processing of the file view_edit.shtm of the component SVG File Handler. Such manipulation of the argument backgroundImageMP leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Exploits (1)
github
WRITEUP
by KarinaGante · htmlpoc
https://github.com/KarinaGante/KG-Sec/tree/main/CVEs/Scada-LTS/CVE-2025-9145.md
References (5)
Scores
CVSS v3
3.5
EPSS
0.0003
EPSS Percentile
7.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Classification
CWE
CWE-94
CWE-79
Status
published
Affected Products (1)
scada-lts/scada-lts
Timeline
Published
Aug 19, 2025
Tracked Since
Feb 18, 2026