Cross-Site Scripting Vulnerability in Scada-LTS by Marcelomulder
CVE-2025-8743

3.5LOW

Key Information:

Status
Vendor
CVE Published:
8 August 2025

What is CVE-2025-8743?

A cross-site scripting vulnerability has been identified in Scada-LTS, specifically in the Virtual Data Source Property Handler component. The flaw arises from improper handling of user input in the '/data_source_edit.shtm' file, particularly the processing of the 'Name' argument. This vulnerability can be exploited remotely, allowing attackers to execute malicious scripts in the context of a user session. The issue is now publicly disclosed, increasing the risk of exploitation, and underscores the importance of mitigating such vulnerabilities through timely updates and security practices.

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2025-8743 : Cross-Site Scripting Vulnerability in Scada-LTS by Marcelomulder