Vendor CVEs
Scada Lts
All CVEs
54 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-24865 | Cri | 0.69 | 10.0 | 0.07 | Feb 13, 2025 | The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload files without the associated password. | ||
| CVE-2022-2234 | Cri | 0.68 | 9.9 | 0.41 | Aug 24, 2022 | An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating system. | ||
| CVE-2021-44453 | Cri | 0.65 | 10.0 | 0.01 | Dec 23, 2021 | mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow an attacker to inject arbitrary operating system commands. | ||
| CVE-2021-43984 | Cri | 0.65 | 10.0 | 0.01 | Dec 23, 2021 | mySCADA myPRO: Versions 8.20.0 and prior has a feature where the firmware can be updated, which may allow an attacker to inject arbitrary operating system commands through a specific parameter. | ||
| CVE-2021-43981 | Cri | 0.65 | 10.0 | 0.01 | Dec 23, 2021 | mySCADA myPRO: Versions 8.20.0 and prior has a feature to send emails, which may allow an attacker to inject arbitrary operating system commands through a specific parameter. | ||
| CVE-2021-23198 | Cri | 0.65 | 10.0 | 0.01 | Dec 23, 2021 | mySCADA myPRO: Versions 8.20.0 and prior has a feature where the password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter. | ||
| CVE-2021-22657 | Cri | 0.65 | 10.0 | 0.01 | Dec 23, 2021 | mySCADA myPRO: Versions 8.20.0 and prior has a feature where the API password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter. | ||
| CVE-2026-19656 | Cri | 0.64 | 9.9 | 0.00 | Aug 12, 2026 | ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary operating system commands on the host. Successful exploitation results in code… | ||
| CVE-2025-25067 | Cri | 0.64 | 9.8 | 0.02 | Feb 13, 2025 | mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands. | ||
| CVE-2025-20061 | Cri | 0.64 | 9.8 | 0.01 | Jan 29, 2025 | mySCADA myPRO does not properly neutralize POST requests sent to a specific port with email information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system. | ||
| CVE-2025-20014 | Cri | 0.64 | 9.8 | 0.01 | Jan 29, 2025 | mySCADA myPRO does not properly neutralize POST requests sent to a specific port with version information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system. | ||
| CVE-2024-4708 | Cri | 0.64 | 9.8 | 0.01 | Jul 2, 2024 | mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device. | ||
| CVE-2023-28384 | Hig | 0.64 | 8.8 | 0.45 | Apr 27, 2023 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. | ||
| CVE-2022-41976 | Cri | 0.64 | 9.9 | 0.02 | Apr 10, 2023 | An privilege escalation issue was discovered in Scada-LTS 2.7.1.1 build 2948559113 allows remote attackers, authenticated in the application as a low-privileged user to change role (e.g., to administrator) by updating their user profile. | ||
| CVE-2021-43987 | Cri | 0.64 | 9.8 | 0.01 | Dec 23, 2021 | An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not exposed through the web interface, which cannot be deleted or changed through the regular web interface. | ||
| CVE-2018-11311 | Cri | 0.63 | 9.1 | 0.16 | May 20, 2018 | A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files or list directories, by entering these credentials. | ||
| CVE-2025-22896 | Hig | 0.59 | 8.6 | 0.03 | Feb 13, 2025 | mySCADA myPRO Manager stores credentials in cleartext, which could allow an attacker to obtain sensitive information. | ||
| CVE-2023-28400 | Hig | 0.59 | 8.8 | 0.25 | Apr 27, 2023 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. | ||
| CVE-2021-43985 | Cri | 0.59 | 9.1 | 0.02 | Dec 23, 2021 | An unauthenticated remote attacker can access mySCADA myPRO Versions 8.20.0 and prior without any form of authentication or authorization. | ||
| CVE-2023-28716 | Hig | 0.58 | 8.8 | 0.04 | Apr 27, 2023 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. | ||
| CVE-2023-33472 | Hig | 0.57 | 8.8 | 0.01 | Jan 13, 2024 | An issue was discovered in Scada-LTS v2.7.5.2 build 4551883606 and before, allows remote attackers with low-level authentication to escalate privileges, execute arbitrary code, and obtain sensitive information via Event Handlers function. | ||
| CVE-2023-29169 | Hig | 0.57 | 8.8 | 0.01 | Apr 27, 2023 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. | ||
| CVE-2023-29150 | Hig | 0.57 | 8.8 | 0.01 | Apr 27, 2023 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. | ||
| CVE-2022-0999 | Hig | 0.57 | 8.8 | 0.01 | Apr 11, 2022 | An authenticated user may be able to misuse parameters to inject arbitrary operating system commands into mySCADA myPRO versions 8.25.0 and prior. | ||
| CVE-2021-33013 | Hig | 0.53 | 8.2 | 0.01 | May 13, 2022 | mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive system information. | ||
| CVE-2021-41578 | Hig | 0.52 | 7.8 | 0.11 | Oct 4, 2021 | mySCADA myDESIGNER 8.20.0 and below allows Directory Traversal attacks when importing project files. If an attacker can trick a victim into importing a malicious mep file, then they gain the ability to write arbitrary files to OS locations where the user has permission. This… | ||
| CVE-2017-12730 | Hig | 0.51 | 7.8 | 0.01 | Oct 6, 2017 | An Unquoted Search Path issue was discovered in mySCADA myPRO Versions 7.0.26 and prior. Application services utilize unquoted search path elements, which could allow an attacker to execute arbitrary code with elevated privileges. | ||
| CVE-2021-43555 | Hig | 0.50 | 7.3 | 0.38 | Nov 19, 2021 | mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may make the product vulnerable to a path traversal payload. This vulnerability may allow an attacker to plant files on the file system in arbitrary locations or… | ||
| CVE-2021-33009 | Hig | 0.49 | 7.5 | 0.01 | May 13, 2022 | mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to the file system. | ||
| CVE-2021-33005 | Hig | 0.49 | 7.5 | 0.02 | May 13, 2022 | mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to arbitrary directories. | ||
| CVE-2021-27505 | Hig | 0.49 | 7.5 | 0.01 | May 13, 2022 | mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive directory listing information. | ||
| CVE-2021-43989 | Hig | 0.49 | 7.5 | 0.01 | Dec 23, 2021 | mySCADA myPRO Versions 8.20.0 and prior stores passwords using MD5, which may allow an attacker to crack the previously retrieved password hashes. | ||
| CVE-2025-13791 | Med | 0.41 | 6.3 | 0.00 | Nov 30, 2025 | A vulnerability was identified in Scada-LTS up to 2.7.8.1. Affected is the function Common.getHomeDir of the file br/org/scadabr/vo/exporter/ZIPProjectManager.java of the component Project Import. Such manipulation leads to path traversal. The attack may be launched remotely.… | ||
| CVE-2025-23411 | Med | 0.41 | 6.3 | 0.01 | Feb 13, 2025 | mySCADA myPRO Manager is vulnerable to cross-site request forgery (CSRF), which could allow an attacker to obtain sensitive information. An attacker would need to trick the victim in to visiting an attacker-controlled website. | ||
| CVE-2026-19657 | Med | 0.40 | 6.1 | 0.00 | Aug 12, 2026 | ScadaLTS 2.7.8.1 reflects user-supplied input into an HTML response without sanitization. An unauthenticated attacker who lures a victim into visiting a crafted URL can execute arbitrary JavaScript in the context of the victim's browser session. | ||
| CVE-2018-11517 | Med | 0.35 | 5.3 | 0.02 | May 28, 2018 | mySCADA myPRO 7 allows remote attackers to discover all ProjectIDs in a project by sending all of the prj parameter values from 870000 to 875000 in t=0&rq=0 requests to TCP port 11010. | ||
| CVE-2025-13790 | Med | 0.28 | 4.3 | 0.00 | Nov 30, 2025 | A vulnerability was determined in Scada-LTS up to 2.7.8.1. This impacts an unknown function. This manipulation causes cross-site request forgery. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early… | ||
| CVE-2025-9139 | Med | 0.28 | 4.3 | 0.00 | Aug 19, 2025 | A vulnerability was determined in Scada-LTS 2.7.8.1. Affected by this vulnerability is an unknown functionality of the file /Scada-LTS/dwr/call/plaincall/WatchListDwr.init.dwr. Executing manipulation can lead to information disclosure. The attack may be performed from a remote… | ||
| CVE-2025-9388 | Low | 0.23 | 3.5 | 0.00 | Aug 24, 2025 | A vulnerability was determined in Scada-LTS up to 2.7.8.1. This impacts an unknown function of the file watch_list.shtm. Executing manipulation of the argument Name can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been publicly… | ||
| CVE-2025-9235 | Low | 0.23 | 3.5 | 0.00 | Aug 20, 2025 | A flaw has been found in Scada-LTS up to 2.7.8.1. The impacted element is an unknown function of the file compound_events.shtm. This manipulation of the argument Name causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published… | ||
| CVE-2025-9234 | Low | 0.23 | 3.5 | 0.00 | Aug 20, 2025 | A vulnerability was detected in Scada-LTS up to 2.7.8.1. The affected element is an unknown function of the file maintenance_events.shtm. The manipulation of the argument Alias results in cross site scripting. The attack can be executed remotely. The exploit is now public and… | ||
| CVE-2025-9233 | Low | 0.23 | 3.5 | 0.00 | Aug 20, 2025 | A security vulnerability has been detected in Scada-LTS up to 2.7.8.1. Impacted is an unknown function of the file view_edit.shtm. The manipulation of the argument Name leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed… | ||
| CVE-2025-9145 | Low | 0.23 | 3.5 | 0.00 | Aug 19, 2025 | A security vulnerability has been detected in Scada-LTS 2.7.8.1. This issue affects some unknown processing of the file view_edit.shtm of the component SVG File Handler. Such manipulation of the argument backgroundImageMP leads to cross site scripting. The attack can be launched… | ||
| CVE-2025-9144 | Low | 0.23 | 3.5 | 0.00 | Aug 19, 2025 | A weakness has been identified in Scada-LTS 2.7.8.1. This vulnerability affects unknown code of the file publisher_edit.shtm. This manipulation of the argument Name causes cross site scripting. The attack can be initiated remotely. The exploit has been made available to the… | ||
| CVE-2025-9143 | Low | 0.23 | 3.5 | 0.00 | Aug 19, 2025 | A security flaw has been discovered in Scada-LTS 2.7.8.1. This affects an unknown part of the file mailing_lists.shtm. The manipulation of the argument name/userList/address results in cross site scripting. It is possible to launch the attack remotely. The exploit has been… | ||
| CVE-2025-9138 | Low | 0.23 | 3.5 | 0.00 | Aug 19, 2025 | A vulnerability was found in Scada-LTS 2.7.8.1. Affected is an unknown function of the file pointHierarchy/new/. Performing manipulation of the argument Title results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been made public and… | ||
| CVE-2025-9137 | Low | 0.23 | 3.5 | 0.00 | Aug 19, 2025 | A vulnerability has been found in Scada-LTS 2.7.8.1. This impacts an unknown function of the file scheduled_events.shtm. Such manipulation of the argument alias leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed to the public and… | ||
| CVE-2025-8743 | Low | 0.23 | 3.5 | 0.00 | Aug 8, 2025 | A vulnerability classified as problematic has been found in Scada-LTS up to 2.7.8.1. This affects an unknown part of the file /data_source_edit.shtm of the component Virtual Data Source Property Handler. The manipulation of the argument Name leads to cross site scripting. It is… | ||
| CVE-2025-7729 | Low | 0.23 | 3.5 | 0.00 | Jul 17, 2025 | A vulnerability classified as problematic was found in Scada-LTS up to 2.7.8.1. Affected by this vulnerability is an unknown functionality of the file usersProfiles.shtm. The manipulation of the argument Username leads to cross site scripting. The attack can be launched… | ||
| CVE-2025-7728 | Low | 0.23 | 3.5 | 0.00 | Jul 17, 2025 | A vulnerability classified as problematic has been found in Scada-LTS up to 2.7.8.1. Affected is an unknown function of the file users.shtm. The manipulation of the argument Username leads to cross site scripting. It is possible to launch the attack remotely. The exploit has… |
- risk 0.69cvss 10.0epss 0.07
The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload files without the associated password.
- risk 0.68cvss 9.9epss 0.41
An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating system.
- risk 0.65cvss 10.0epss 0.01
mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow an attacker to inject arbitrary operating system commands.
- risk 0.65cvss 10.0epss 0.01
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the firmware can be updated, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
- risk 0.65cvss 10.0epss 0.01
mySCADA myPRO: Versions 8.20.0 and prior has a feature to send emails, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
- risk 0.65cvss 10.0epss 0.01
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
- risk 0.65cvss 10.0epss 0.01
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the API password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
- risk 0.64cvss 9.9epss 0.00
ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary operating system commands on the host. Successful exploitation results in code…
- risk 0.64cvss 9.8epss 0.02
mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands.
- risk 0.64cvss 9.8epss 0.01
mySCADA myPRO does not properly neutralize POST requests sent to a specific port with email information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system.
- risk 0.64cvss 9.8epss 0.01
mySCADA myPRO does not properly neutralize POST requests sent to a specific port with version information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system.
- risk 0.64cvss 9.8epss 0.01
mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device.
- risk 0.64cvss 8.8epss 0.45
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
- risk 0.64cvss 9.9epss 0.02
An privilege escalation issue was discovered in Scada-LTS 2.7.1.1 build 2948559113 allows remote attackers, authenticated in the application as a low-privileged user to change role (e.g., to administrator) by updating their user profile.
- risk 0.64cvss 9.8epss 0.01
An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not exposed through the web interface, which cannot be deleted or changed through the regular web interface.
- risk 0.63cvss 9.1epss 0.16
A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files or list directories, by entering these credentials.
- risk 0.59cvss 8.6epss 0.03
mySCADA myPRO Manager stores credentials in cleartext, which could allow an attacker to obtain sensitive information.
- risk 0.59cvss 8.8epss 0.25
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
- risk 0.59cvss 9.1epss 0.02
An unauthenticated remote attacker can access mySCADA myPRO Versions 8.20.0 and prior without any form of authentication or authorization.
- risk 0.58cvss 8.8epss 0.04
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in Scada-LTS v2.7.5.2 build 4551883606 and before, allows remote attackers with low-level authentication to escalate privileges, execute arbitrary code, and obtain sensitive information via Event Handlers function.
- risk 0.57cvss 8.8epss 0.01
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
- risk 0.57cvss 8.8epss 0.01
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
- risk 0.57cvss 8.8epss 0.01
An authenticated user may be able to misuse parameters to inject arbitrary operating system commands into mySCADA myPRO versions 8.25.0 and prior.
- risk 0.53cvss 8.2epss 0.01
mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive system information.
- risk 0.52cvss 7.8epss 0.11
mySCADA myDESIGNER 8.20.0 and below allows Directory Traversal attacks when importing project files. If an attacker can trick a victim into importing a malicious mep file, then they gain the ability to write arbitrary files to OS locations where the user has permission. This…
- risk 0.51cvss 7.8epss 0.01
An Unquoted Search Path issue was discovered in mySCADA myPRO Versions 7.0.26 and prior. Application services utilize unquoted search path elements, which could allow an attacker to execute arbitrary code with elevated privileges.
- risk 0.50cvss 7.3epss 0.38
mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may make the product vulnerable to a path traversal payload. This vulnerability may allow an attacker to plant files on the file system in arbitrary locations or…
- risk 0.49cvss 7.5epss 0.01
mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to the file system.
- risk 0.49cvss 7.5epss 0.02
mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to arbitrary directories.
- risk 0.49cvss 7.5epss 0.01
mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive directory listing information.
- risk 0.49cvss 7.5epss 0.01
mySCADA myPRO Versions 8.20.0 and prior stores passwords using MD5, which may allow an attacker to crack the previously retrieved password hashes.
- risk 0.41cvss 6.3epss 0.00
A vulnerability was identified in Scada-LTS up to 2.7.8.1. Affected is the function Common.getHomeDir of the file br/org/scadabr/vo/exporter/ZIPProjectManager.java of the component Project Import. Such manipulation leads to path traversal. The attack may be launched remotely.…
- risk 0.41cvss 6.3epss 0.01
mySCADA myPRO Manager is vulnerable to cross-site request forgery (CSRF), which could allow an attacker to obtain sensitive information. An attacker would need to trick the victim in to visiting an attacker-controlled website.
- risk 0.40cvss 6.1epss 0.00
ScadaLTS 2.7.8.1 reflects user-supplied input into an HTML response without sanitization. An unauthenticated attacker who lures a victim into visiting a crafted URL can execute arbitrary JavaScript in the context of the victim's browser session.
- risk 0.35cvss 5.3epss 0.02
mySCADA myPRO 7 allows remote attackers to discover all ProjectIDs in a project by sending all of the prj parameter values from 870000 to 875000 in t=0&rq=0 requests to TCP port 11010.
- risk 0.28cvss 4.3epss 0.00
A vulnerability was determined in Scada-LTS up to 2.7.8.1. This impacts an unknown function. This manipulation causes cross-site request forgery. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early…
- risk 0.28cvss 4.3epss 0.00
A vulnerability was determined in Scada-LTS 2.7.8.1. Affected by this vulnerability is an unknown functionality of the file /Scada-LTS/dwr/call/plaincall/WatchListDwr.init.dwr. Executing manipulation can lead to information disclosure. The attack may be performed from a remote…
- risk 0.23cvss 3.5epss 0.00
A vulnerability was determined in Scada-LTS up to 2.7.8.1. This impacts an unknown function of the file watch_list.shtm. Executing manipulation of the argument Name can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been publicly…
- risk 0.23cvss 3.5epss 0.00
A flaw has been found in Scada-LTS up to 2.7.8.1. The impacted element is an unknown function of the file compound_events.shtm. This manipulation of the argument Name causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published…
- risk 0.23cvss 3.5epss 0.00
A vulnerability was detected in Scada-LTS up to 2.7.8.1. The affected element is an unknown function of the file maintenance_events.shtm. The manipulation of the argument Alias results in cross site scripting. The attack can be executed remotely. The exploit is now public and…
- risk 0.23cvss 3.5epss 0.00
A security vulnerability has been detected in Scada-LTS up to 2.7.8.1. Impacted is an unknown function of the file view_edit.shtm. The manipulation of the argument Name leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed…
- risk 0.23cvss 3.5epss 0.00
A security vulnerability has been detected in Scada-LTS 2.7.8.1. This issue affects some unknown processing of the file view_edit.shtm of the component SVG File Handler. Such manipulation of the argument backgroundImageMP leads to cross site scripting. The attack can be launched…
- risk 0.23cvss 3.5epss 0.00
A weakness has been identified in Scada-LTS 2.7.8.1. This vulnerability affects unknown code of the file publisher_edit.shtm. This manipulation of the argument Name causes cross site scripting. The attack can be initiated remotely. The exploit has been made available to the…
- risk 0.23cvss 3.5epss 0.00
A security flaw has been discovered in Scada-LTS 2.7.8.1. This affects an unknown part of the file mailing_lists.shtm. The manipulation of the argument name/userList/address results in cross site scripting. It is possible to launch the attack remotely. The exploit has been…
- risk 0.23cvss 3.5epss 0.00
A vulnerability was found in Scada-LTS 2.7.8.1. Affected is an unknown function of the file pointHierarchy/new/. Performing manipulation of the argument Title results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been made public and…
- risk 0.23cvss 3.5epss 0.00
A vulnerability has been found in Scada-LTS 2.7.8.1. This impacts an unknown function of the file scheduled_events.shtm. Such manipulation of the argument alias leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed to the public and…
- risk 0.23cvss 3.5epss 0.00
A vulnerability classified as problematic has been found in Scada-LTS up to 2.7.8.1. This affects an unknown part of the file /data_source_edit.shtm of the component Virtual Data Source Property Handler. The manipulation of the argument Name leads to cross site scripting. It is…
- risk 0.23cvss 3.5epss 0.00
A vulnerability classified as problematic was found in Scada-LTS up to 2.7.8.1. Affected by this vulnerability is an unknown functionality of the file usersProfiles.shtm. The manipulation of the argument Username leads to cross site scripting. The attack can be launched…
- risk 0.23cvss 3.5epss 0.00
A vulnerability classified as problematic has been found in Scada-LTS up to 2.7.8.1. Affected is an unknown function of the file users.shtm. The manipulation of the argument Username leads to cross site scripting. It is possible to launch the attack remotely. The exploit has…
Page 1 of 2