CVE-2025-34080: CONPROSYS HMI System (CHS) < 3.7.7 Reflected Cross-Site Scripting
Published Jul 1, 2025
·Updated
The Contec Co.,Ltd. CONPROSYS HMI System (CHS) is vulnerable to Cross-Site Scripting (XSS) in the getqsetting.php functionality that could allow reflected execution of scripts in the browser on interaction.This issue affects CONPROSYS HMI System (CHS): before 3.7.7.
Affected Software
2 affected components
Contec CONPROSYS HMI System (CHS)<3.7.7
Contec CONPROSYS HMI System<3.7.7
Event History
Jul 1, 2025
CVE Published
via MITRE·05:51 PM
Data Sourced
via MITRE·05:51 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-34080?
CVE-2025-34080 has a medium severity rating due to its potential for reflected XSS attacks.
2
How do I fix CVE-2025-34080?
To fix CVE-2025-34080, upgrade the CONPROSYS HMI System (CHS) to version 3.7.7 or later.
3
What product is affected by CVE-2025-34080?
CVE-2025-34080 affects the Contec Co.,Ltd. CONPROSYS HMI System (CHS) versions prior to 3.7.7.
4
What types of attacks can be executed via CVE-2025-34080?
CVE-2025-34080 could allow attackers to execute reflected Cross-Site Scripting (XSS) attacks in the browser.
5
When was CVE-2025-34080 publicly disclosed?
CVE-2025-34080 was publicly disclosed in 2025.