CVE-2025-9404: Scada-LTS Folder pointHierarchySLTS cross site scripting
A vulnerability was identified in Scada-LTS up to 2.7.8.1. The affected element is an unknown function of the file /pointHierarchySLTS of the component Folder Handler. The manipulation of the argument Title leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9404?
CVE-2025-9404 is classified as a cross-site scripting (XSS) vulnerability, which can lead to unauthorized access and data manipulation.
How do I fix CVE-2025-9404?
To fix CVE-2025-9404, update Scada-LTS to version 2.7.8.2 or later, which addresses the vulnerability.
What versions of Scada-LTS are affected by CVE-2025-9404?
CVE-2025-9404 affects all versions of Scada-LTS up to and including 2.7.8.1.
Can CVE-2025-9404 be exploited remotely?
Yes, CVE-2025-9404 can be exploited remotely through crafted input sent to the vulnerable Folder Handler component.
What impact does CVE-2025-9404 have on users?
The impact of CVE-2025-9404 includes potential data theft, session hijacking, and execution of malicious scripts in the context of the user's browser.