Impact
ITS Intelligent SCADA System contains a stored cross‑site scripting flaw that lets privileged remote attackers inject persistent JavaScript into the system. When other users load affected pages, the malicious script runs automatically in their browsers, enabling attackers to steal credentials, exfiltrate data or perform other malicious actions.
Affected Systems
The vulnerability affects ITP Technology’s ITS Intelligent SCADA System. No specific version information is provided in the advisory, so all deployments of the product should be treated as potentially affected.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate impact, and the lack of an EPSS score means the current exploit probability is unclear. Because the flaw is stored, an attacker with privileged access can embed the payload on behalf of other users, raising the attack surface. The vulnerability is not listed in CISA KEV. The likely attack vector is an authenticated privileged user inserting malicious content that is later rendered for all users; a simple remote attacker without credentials would not be able to exploit this directly.
OpenCVE Enrichment