CVE-2025-10234: Scada-LTS Data Point Edit data_point_edit.shtm cross site scripting
A vulnerability was detected in Scada-LTS up to 2.7.8.1. This vulnerability affects unknown code of the file /datapointedit.shtm of the component Data Point Edit Module. The manipulation of the argument Text Renderer properties results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10234?
CVE-2025-10234 has a moderate severity level due to its potential for cross-site scripting attacks.
How do I fix CVE-2025-10234?
To fix CVE-2025-10234, you should update the Scada-LTS Data Point Edit Module to version 2.7.8.2 or later.
What systems are affected by CVE-2025-10234?
CVE-2025-10234 affects Scada-LTS Data Point Edit Module versions up to and including 2.7.8.1.
What type of vulnerability is CVE-2025-10234?
CVE-2025-10234 is classified as a cross-site scripting (XSS) vulnerability.
Can CVE-2025-10234 be exploited remotely?
Yes, CVE-2025-10234 can be exploited remotely if an attacker manipulates the vulnerable input fields.