Skip to main content
Vulnerability Database/CVE-2025-10235

CVE-2025-10235: Scada-LTS Reports Module XSS Vulnerability

CVE-2025-10235 is a cross-site scripting flaw in Scada-LTS Reports Module affecting versions up to 2.7.8.1. Attackers can exploit the Colour parameter to inject malicious scripts. This article covers technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2025-10235 Overview

CVE-2025-10235 is a stored cross-site scripting (XSS) vulnerability in Scada-LTS versions up to and including 2.7.8.1. The flaw resides in the Reports Module accessible via /reports.shtm, where the Colour parameter is not properly sanitized before being rendered. An authenticated attacker with high privileges can inject persistent JavaScript payloads that execute in the context of other users who view the affected report. The vulnerability is tracked under [CWE-79] and has been publicly disclosed, including a detailed technical writeup. The vendor was contacted early about this disclosure but did not respond.

Critical Impact

Stored JavaScript payloads execute in the browsers of Scada-LTS operators viewing crafted reports, enabling session theft, UI manipulation, and pivot attacks against SCADA operator workstations.

Affected Products

  • Scada-LTS versions up to and including 2.7.8.1
  • Component: Reports Module (/reports.shtm)
  • Vulnerable parameter: Colour

Discovery Timeline

  • 2025-09-11 - CVE-2025-10235 published to the National Vulnerability Database
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-10235

Vulnerability Analysis

The vulnerability is a stored cross-site scripting flaw [CWE-79] in the Scada-LTS Reports Module. When a user creates or edits a report through /reports.shtm, the application accepts a Colour argument that is persisted to the backend without adequate output encoding or input validation. When the report is later rendered, the stored value is reflected into the HTML response, allowing any script content submitted through Colour to execute in the victim's browser session. Because Scada-LTS is a web front-end for industrial control systems, malicious script execution in an operator's browser can affect operational visibility and control workflows.

Root Cause

The root cause is missing contextual output encoding on the Colour field when it is rendered into report views. The application treats the field as trusted styling metadata rather than untrusted user input, so HTML and JavaScript tokens pass through unmodified. Refer to the Medium Stored XSS Analysis for the full technical writeup.

Attack Vector

Exploitation requires network access to the Scada-LTS web interface and an authenticated account with sufficient privileges to create or modify reports. The attacker submits a crafted value into the Colour field via /reports.shtm. The payload is stored server-side and executes whenever another user, including operators or administrators, loads the affected report. Because interaction from a second user is required to trigger the payload, the attack chains social engineering or normal operational workflow with the initial injection. Additional details are available in the VulDB CTI entry #323504.

Detection Methods for CVE-2025-10235

Indicators of Compromise

  • Report definitions containing HTML tags, <script> elements, or JavaScript event handlers (onerror, onload, onmouseover) inside the Colour field.
  • Unexpected outbound HTTP requests from operator browsers to attacker-controlled domains shortly after loading /reports.shtm.
  • New or modified report entries created by unusual accounts or outside normal maintenance windows.

Detection Strategies

  • Inspect the Scada-LTS report datastore for Colour values that do not match expected hex color or named color patterns (for example, ^#[0-9A-Fa-f]{6}$).
  • Review web server access logs for POST requests to /reports.shtm containing URL-encoded angle brackets, script, or event handler keywords in form fields.
  • Enable browser Content Security Policy (CSP) violation reporting to surface unexpected inline script execution originating from Scada-LTS pages.

Monitoring Recommendations

  • Alert on authenticated report creation or modification events performed by accounts that do not normally administer reporting.
  • Monitor operator workstation processes for anomalous child browser activity, credential access, or lateral movement following Scada-LTS sessions.
  • Correlate Scada-LTS application logs with network egress data to identify script-driven data exfiltration.

How to Mitigate CVE-2025-10235

Immediate Actions Required

  • Restrict access to the Scada-LTS web interface to trusted management networks and jump hosts only.
  • Audit existing reports for injected HTML or JavaScript in the Colour field and remove or reset any offending entries.
  • Reduce the number of accounts with permission to create or modify reports, applying least-privilege principles.
  • Require operators to use a hardened, dedicated browser profile when accessing Scada-LTS.

Patch Information

As of the last NVD update on 2026-06-17, no vendor-issued patch is referenced for CVE-2025-10235, and the vendor did not respond to disclosure attempts. Track the VulDB entry #323504 for updates and monitor the Scada-LTS project repository for future releases beyond 2.7.8.1.

Workarounds

  • Deploy a reverse proxy or web application firewall (WAF) rule that rejects POST bodies to /reports.shtm containing HTML tags or JavaScript keywords in the Colour parameter.
  • Enforce a strict Content Security Policy that disallows inline scripts (script-src 'self') on Scada-LTS responses to neutralize injected payloads.
  • Segment SCADA operator workstations from general corporate networks to limit the impact of a compromised browser session.
bash
# Example NGINX reverse-proxy rule to block obvious XSS payloads in the Colour field
location /reports.shtm {
    if ($request_method = POST) {
        set $block 0;
        if ($request_body ~* "Colour=[^&]*(<|%3C|script|onerror|onload)") { set $block 1; }
        if ($block = 1) { return 403; }
    }
    proxy_pass http://scada_lts_backend;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.