CVE-2025-7729: Scada-LTS usersProfiles.shtm cross site scripting
A vulnerability classified as problematic was found in Scada-LTS up to 2.7.8.1. Affected by this vulnerability is an unknown functionality of the file usersProfiles.shtm. The manipulation of the argument Username leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this issue and confirmed that it will be fixed in the upcoming release 2.8.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Scada-LTSto a version that resolves this vulnerability.Fixed in 2.8.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7729?
CVE-2025-7729 is classified as problematic and involves a cross-site scripting vulnerability.
How do I fix CVE-2025-7729?
To fix CVE-2025-7729, validate and sanitize user input for the Username argument in usersProfiles.shtm.
Who is affected by CVE-2025-7729?
CVE-2025-7729 affects Scada-LTS versions up to 2.7.8.1.
What type of attack is associated with CVE-2025-7729?
CVE-2025-7729 is associated with remote cross-site scripting (XSS) attacks.
Can CVE-2025-7729 be exploited remotely?
Yes, CVE-2025-7729 can be exploited remotely by manipulating the Username argument.