CVE-2025-7728: Scada-LTS users.shtm cross site scripting
A vulnerability classified as problematic has been found in Scada-LTS up to 2.7.8.1. Affected is an unknown function of the file users.shtm. The manipulation of the argument Username leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this issue and confirmed that it will be fixed in the upcoming release 2.8.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Scada-LTSto a version that resolves this vulnerability.Fixed in 2.8.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7728?
CVE-2025-7728 is classified as a problematic vulnerability.
How do I fix CVE-2025-7728?
To fix CVE-2025-7728, update Scada-LTS to a version newer than 2.7.8.1.
What type of vulnerability is CVE-2025-7728?
CVE-2025-7728 is a cross-site scripting (XSS) vulnerability.
Is CVE-2025-7728 remotely exploitable?
Yes, CVE-2025-7728 can be exploited remotely.
Which software is affected by CVE-2025-7728?
CVE-2025-7728 affects Scada-LTS versions up to 2.7.8.1.