Cross-Site Scripting Vulnerability in Schneider Electric Products
CVE-2025-13902

5.1MEDIUM

What is CVE-2025-13902?

A Cross-Site Scripting (XSS) vulnerability exists in various Schneider Electric products due to improper neutralization of input during the generation of web pages. This flaw allows authenticated attackers to craft malicious elements that, when hovered over by a victim, can prompt their browser to execute arbitrary JavaScript code. This potential exposure underscores the importance of securing web applications to prevent exploitation and protect user data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Modicon Controllers M241/M251 Versions prior to 5.4.13.12

Modicon Controllers M258/LMC058 All versions

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.