Cross-site Scripting Vulnerability in Schneider Electric Products
CVE-2025-3117

5.1MEDIUM

What is CVE-2025-3117?

This vulnerability arises from improper neutralization of user input during the generation of web pages, specifically impacting Schneider Electric's configuration file paths. An authenticated malicious user may exploit this weakness to inject unvalidated data, potentially allowing them to read or modify data in a victim's browser. Organizations using affected Schneider Electric products should apply recommended patches and review their security configurations to mitigate potential risks.

Affected Version(s)

Modicon Controllers M241/M251 Versions prior to 5.3.12.51

Modicon Controllers M262 Versions prior to 5.3.9.18

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-3117 : Cross-site Scripting Vulnerability in Schneider Electric Products