VYPR
Unrated severityNVD Advisory· Published Jul 1, 2025· Updated Nov 21, 2025

CONPROSYS HMI System (CHS) < 3.7.7 Reflected Cross-Site Scripting

CVE-2025-34080

Description

The Contec Co.,Ltd. CONPROSYS HMI System (CHS) is vulnerable to Cross-Site Scripting (XSS) in the getqsetting.php functionality that could allow reflected execution of scripts in the browser on interaction.This issue affects CONPROSYS HMI System (CHS): before 3.7.7.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.