Unrated severityNVD Advisory· Published Jul 1, 2025· Updated Nov 21, 2025
CONPROSYS HMI System (CHS) < 3.7.7 Reflected Cross-Site Scripting
CVE-2025-34080
Description
The Contec Co.,Ltd. CONPROSYS HMI System (CHS) is vulnerable to Cross-Site Scripting (XSS) in the getqsetting.php functionality that could allow reflected execution of scripts in the browser on interaction.This issue affects CONPROSYS HMI System (CHS): before 3.7.7.
Affected products
2<3.7.7+ 1 more
- (no CPE)range: <3.7.7
- (no CPE)range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- jvn.jp/en/vu/JVNVU92266386/mitrethird-party-advisory
- www.vulncheck.com/advisories/conprosys-hmi-system-reflected-xssmitrethird-party-advisory
News mentions
0No linked articles in our index yet.