Cross-site Scripting Vulnerability in Schneider Electric Products
CVE-2025-3117
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 10 June 2025
What is CVE-2025-3117?
This vulnerability arises from improper neutralization of user input during the generation of web pages, specifically impacting Schneider Electric's configuration file paths. An authenticated malicious user may exploit this weakness to inject unvalidated data, potentially allowing them to read or modify data in a victim's browser. Organizations using affected Schneider Electric products should apply recommended patches and review their security configurations to mitigate potential risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Modicon Controllers M241/M251 Versions prior to 5.3.12.51
Modicon Controllers M262 Versions prior to 5.3.9.18
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved