Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-28830 | A flaw has been found in Scada-LTS up to 2.7.8.1. The impacted element is an unknown function of the file compound_events.shtm. This manipulation of the argument Name causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used. |
Thu, 11 Sep 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:scada-lts:scada-lts:*:*:*:*:*:*:*:* |
Thu, 21 Aug 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Scada-lts
Scada-lts scada-lts |
|
| Vendors & Products |
Scada-lts
Scada-lts scada-lts |
Wed, 20 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 20 Aug 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in Scada-LTS up to 2.7.8.1. The impacted element is an unknown function of the file compound_events.shtm. This manipulation of the argument Name causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used. | |
| Title | Scada-LTS compound_events.shtm cross site scripting | |
| Weaknesses | CWE-79 CWE-94 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-08-20T17:24:42.292Z
Reserved: 2025-08-20T10:52:00.657Z
Link: CVE-2025-9235
Updated: 2025-08-20T17:24:34.882Z
Status : Analyzed
Published: 2025-08-20T17:15:39.037
Modified: 2026-04-29T01:00:01.613
Link: CVE-2025-9235
No data.
OpenCVE Enrichment
Updated: 2025-08-21T12:30:46Z
EUVD