CVE-2025-9145
LOWScada-LTS 2.7.8.1 - Cross-Site Scripting via SVG File Handler backgroundImageMP Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-9145. PoCs published by KarinaGante.
AI-analyzed exploit summary The repository contains a detailed writeup for CVE-2025-9145, focusing on a directory traversal vulnerability in Scada-LTS. It includes technical details, proof-of-concept steps, and screenshots demonstrating the exploit.
Description
A security vulnerability has been detected in Scada-LTS 2.7.8.1. This issue affects some unknown processing of the file view_edit.shtm of the component SVG File Handler. Such manipulation of the argument backgroundImageMP leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Exploits (1)
The repository contains a detailed writeup for CVE-2025-9145, focusing on a directory traversal vulnerability in Scada-LTS. It includes technical details, proof-of-concept steps, and screenshots demonstrating the exploit.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N