CVE-2025-9388

LOW

Scada-LTS <2.7.8.1 - XSS

Title source: llm
STIX 2.1

Description

A vulnerability was determined in Scada-LTS up to 2.7.8.1. This impacts an unknown function of the file watch_list.shtm. Executing manipulation of the argument Name can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.321221
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.321221
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.630800

Scores

CVSS v3 3.5
EPSS 0.0005
EPSS Percentile 17.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79 CWE-94
Status published
Products (1)
scada-lts/scada-lts < 2.7.8.1
Published Aug 24, 2025
Tracked Since Feb 18, 2026