ScadaLTS 2.7.8.1 reflects user-supplied input into an HTML response without sanitization. An unauthenticated attacker who lures a victim into visiting a crafted URL can execute arbitrary JavaScript in the context of the victim's browser session.
References
| Link | Resource |
|---|---|
| https://www.tenable.com/security/research/tra-2026-55 | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-08-12 20:17
Updated : 2026-08-25 13:04
NVD link : CVE-2026-19657
Mitre link : CVE-2026-19657
CVE.ORG link : CVE-2026-19657
JSON object : View
Products Affected
scada-lts
- scada-lts
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
