CVE-2025-10235: Scada-LTS Reports reports.shtm cross site scripting
A flaw has been found in Scada-LTS up to 2.7.8.1. This issue affects some unknown processing of the file /reports.shtm of the component Reports Module. This manipulation of the argument Colour causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10235?
CVE-2025-10235 is classified as a medium severity cross-site scripting vulnerability.
How do I fix CVE-2025-10235?
To fix CVE-2025-10235, upgrade the Scada-LTS Reports Module to a version beyond 2.7.8.1.
What does CVE-2025-10235 affect?
CVE-2025-10235 affects the Reports Module of Scada-LTS up to version 2.7.8.1.
Is CVE-2025-10235 remotely exploitable?
Yes, CVE-2025-10235 can be exploited remotely by manipulating the Colour parameter.
What type of vulnerability is CVE-2025-10235?
CVE-2025-10235 is a cross-site scripting (XSS) vulnerability.