CVE-2025-34080

The Contec Co.,Ltd. CONPROSYS HMI System (CHS) is vulnerable to Cross-Site Scripting (XSS) in the getqsetting.php functionality that could allow reflected execution of scripts in the browser on interaction.This issue affects CONPROSYS HMI System (CHS): before 3.7.7.
References
Link Resource
https://jvn.jp/en/vu/JVNVU92266386/ Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:contec:conprosys_hmi_system:*:*:*:*:*:*:*:*

History

17 Sep 2025, 14:06

Type Values Removed Values Added
First Time Contec
Contec conprosys Hmi System
CPE cpe:2.3:a:contec:conprosys_hmi_system:*:*:*:*:*:*:*:*
References () https://jvn.jp/en/vu/JVNVU92266386/ - () https://jvn.jp/en/vu/JVNVU92266386/ - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

03 Jul 2025, 15:14

Type Values Removed Values Added
Summary
  • (es) Contec Co.,Ltd. CONPROSYS HMI System (CHS) es vulnerable a Cross-Site Scripting (XSS) en la funcionalidad getqsetting.php que podría permitir la ejecución reflejada de secuencias de comandos en el navegador durante la interacción. Este problema afecta al sistema HMI CONPROSYS (CHS): anterior a la versión 3.7.7.

01 Jul 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-01 18:15

Updated : 2025-09-17 14:06


NVD link : CVE-2025-34080

Mitre link : CVE-2025-34080

CVE.ORG link : CVE-2025-34080


JSON object : View

Products Affected

contec

  • conprosys_hmi_system
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')