A flaw has been found in Scada-LTS up to 2.7.8.1. The impacted element is an unknown function of the file compound_events.shtm. This manipulation of the argument Name causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used.
| Software | From | Fixed in |
|---|---|---|
| scada-lts / scada-lts | - | 2.7.8.1.x |