Scada-LTS Stored Cross-Site Scripting Vulnerability in PointHierarchy Endpoint

Vulnerability

A stored cross-site scripting vulnerability has been identified in Scada-LTS version 2.7.8.1. The issue resides in the pointHierarchy/new/ endpoint, where user input in the Title argument is not properly validated or sanitized. This flaw allows for the injection of malicious scripts, which are stored on the server and executed automatically when the page is accessed by users. The vulnerability can be exploited remotely, although it may require administrative permissions.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user accessing the affected page. This could lead to session hijacking, credential theft, delivery of malware, and defacement of websites, among other risks.

Reproduction

To reproduce this vulnerability, access the pointHierarchy/new/ endpoint. Click on the '+' button to add a new entry, then insert a script payload into the Title field. After saving the entry by clicking the 'Yes' button, the injected script will be executed automatically.

Added: Aug 19, 2025, 1:18 PM
Updated: Aug 19, 2025, 1:45 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
1.7
exploitability
5.5
remediation
0.0
relevance
0.4
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.