Contec CONPROSYS HMI System Reflected Cross-Site Scripting Vulnerability

Vulnerability

A reflected cross-site scripting vulnerability has been identified in the Contec CONPROSYS HMI System (CHS) versions prior to 3.7.7. This issue arises in the getqsetting.php functionality, allowing for the execution of arbitrary scripts in the browser upon interaction.

Impact

Exploitation of this vulnerability allows for the execution of arbitrary scripts in the web browser of the user accessing the application.

Remediation

Users are advised to update to CONPROSYS HMI System (CHS) version 3.7.7 or later, which addresses this vulnerability.

Added: Jul 1, 2025, 8:40 PM
Updated: Jul 1, 2025, 8:40 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
1.7
exploitability
6.0
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.