CVE-2025-7729 | Scada-LTS up to 2.7.8.1 usersProfiles.shtm Username cross site scripting (EUVD-2025-21755)
A vulnerability, which was classified as problematic, was found in Scada-LTS up to 2.7.8.1. This impacts an unknown function of the file usersProfiles.shtm. The manipulation of the argument Username results in cross site scripting.
This vulnerability is known as CVE-2025-7729. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this issue and confirmed that it will be fixed in the upcoming release 2.8.0.