CVE-2025-9143: Scada-LTS mailing_lists.shtm cross site scripting
A security flaw has been discovered in Scada-LTS 2.7.8.1. This affects an unknown part of the file mailinglists.shtm. The manipulation of the argument name/userList/address results in cross site scripting. It is possible to launch the attack remotely. The exploit has been released to the public and may be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9143?
CVE-2025-9143 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2025-9143?
To fix CVE-2025-9143, ensure that all user inputs are properly sanitized and validate the data before rendering it on the webpage.
What type of vulnerability is CVE-2025-9143?
CVE-2025-9143 is a cross-site scripting (XSS) vulnerability that allows attackers to manipulate user input.
What can attackers do with CVE-2025-9143?
Attackers exploiting CVE-2025-9143 can execute malicious scripts in the context of a user's browser, potentially leading to data theft or session hijacking.
Which software versions are affected by CVE-2025-9143?
CVE-2025-9143 affects Scada-LTS version 2.7.8.1 and possibly other related versions.