CVE-2025-9234: Scada-LTS maintenance_events.shtm cross site scripting
A vulnerability was detected in Scada-LTS up to 2.7.8.1. The affected element is an unknown function of the file maintenanceevents.shtm. The manipulation of the argument Alias results in cross site scripting. The attack can be executed remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9234?
CVE-2025-9234 is classified as a critical vulnerability due to its potential for remote exploitation through cross-site scripting.
How do I fix CVE-2025-9234?
To fix CVE-2025-9234, update Scada-LTS to version 2.7.8.2 or later where the vulnerability has been addressed.
What systems are affected by CVE-2025-9234?
CVE-2025-9234 affects Scada-LTS versions up to and including 2.7.8.1.
What type of vulnerability is CVE-2025-9234?
CVE-2025-9234 is a cross-site scripting (XSS) vulnerability that can be exploited through manipulation of the argument Alias.
Can CVE-2025-9234 be exploited remotely?
Yes, CVE-2025-9234 can be exploited remotely, allowing attackers to execute malicious scripts in users' browsers.