CVE-2025-7728

A vulnerability classified as problematic has been found in Scada-LTS up to 2.7.8.1. Affected is an unknown function of the file users.shtm. The manipulation of the argument Username leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this issue and confirmed that it will be fixed in the upcoming release 2.8.0.
References
Link Resource
https://github.com/CVE-Hunters/CVE/blob/main/Scada-LTS/CVE-2025-7728.md Exploit Third Party Advisory
https://vuldb.com/?ctiid.316710 Permissions Required VDB Entry
https://vuldb.com/?id.316710 Third Party Advisory VDB Entry
https://vuldb.com/?submit.607949 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:scada-lts:scada-lts:*:*:*:*:*:*:*:*

History

11 Sep 2025, 15:09

Type Values Removed Values Added
Summary
  • (es) Se ha detectado una vulnerabilidad clasificada como problemática en Scada-LTS hasta la versión 2.7.8.1. La vulnerabilidad afecta a una función desconocida del archivo users.shtm. La manipulación del argumento "Username" provoca ataques de cross-site scripting. Es posible ejecutar el ataque en remoto. Se ha hecho público el exploit y puede que sea utilizado. Se contactó con el proveedor con antelación para informarle sobre este problema, quien confirmó que se solucionará en la próxima versión 2.8.0.
References () https://github.com/CVE-Hunters/CVE/blob/main/Scada-LTS/CVE-2025-7728.md - () https://github.com/CVE-Hunters/CVE/blob/main/Scada-LTS/CVE-2025-7728.md - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.316710 - () https://vuldb.com/?ctiid.316710 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.316710 - () https://vuldb.com/?id.316710 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.607949 - () https://vuldb.com/?submit.607949 - Third Party Advisory, VDB Entry
CPE cpe:2.3:a:scada-lts:scada-lts:*:*:*:*:*:*:*:*
First Time Scada-lts scada-lts
Scada-lts

17 Jul 2025, 03:15

Type Values Removed Values Added
References
  • {'url': 'https://github.com/nmmorette/vulnerability-research/blob/main/scada2/README.md', 'source': 'cna@vuldb.com'}
  • () https://github.com/CVE-Hunters/CVE/blob/main/Scada-LTS/CVE-2025-7728.md -

17 Jul 2025, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-17 02:15

Updated : 2025-09-11 15:09


NVD link : CVE-2025-7728

Mitre link : CVE-2025-7728

CVE.ORG link : CVE-2025-7728


JSON object : View

Products Affected

scada-lts

  • scada-lts
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')