CVE-2025-9137 (CNNVD-202508-2087)
中文标题:
Scada-LTS 代码注入漏洞
英文标题:
Scada-LTS scheduled_events.shtm cross site scripting
漏洞描述
中文描述:
Scada-LTS是Scada-LTS开源的一个开源、基于 web 的多平台解决方案。 Scada-LTS 2.7.8.1版本存在代码注入漏洞,该漏洞源于scheduled_events.shtm文件alias参数操作不当,可能导致跨站脚本攻击。
英文描述:
A vulnerability has been found in Scada-LTS 2.7.8.1. This impacts an unknown function of the file scheduled_events.shtm. Such manipulation of the argument alias leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor explains: "[T]he risks of indicated vulnerabilities seem to be minimal as all scenarios likely require admin permissions. Moreover, regardless our team fixes those vulnerabilities - the overall risk change to the user due to malicious admin actions will not be lower. An admin user - by definition - has full control over HTML and JS code that is delivered to users in regular synoptic panels. In other words - due to the design of the system it is not possible to limit the admin user to attack the users."
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| scada-lts | scada-lts | 2.7.8.1 | - | - |
cpe:2.3:a:scada-lts:scada-lts:2.7.8.1:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
cve.org
cve.org
nvd.nist.gov
nvd.nist.gov
CVSS评分详情
4.0 (cna)
MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
3.1 (cna)
LOWCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R
3.0 (cna)
LOWCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R
2.0 (cna)
MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-9137 |
2025-11-11 15:23:37 | 2025-11-11 07:40:54 |
| NVD | nvd_CVE-2025-9137 |
2025-11-11 15:00:59 | 2025-11-11 07:48:40 |
| CNNVD | cnnvd_CNNVD-202508-2087 |
2025-11-11 15:12:54 | 2025-11-11 08:00:05 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 代码注入
- cnnvd_id: 未提取 -> CNNVD-202508-2087
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 0 -> 1
- references_count: 5 -> 7
- data_sources: ['cve'] -> ['cve', 'nvd']