Junglewise Threat Intelligence

CVE-2026-10057: ITP Technology ITS Intelligent SCADA System Stored XSS

CVE-2026-10057 · Severity: medium · CVSS 4.8 · Published 2026-05-29

Executive brief

The ITS Intelligent SCADA System, used for monitoring and controlling industrial processes, contains a security flaw that allows an attacker with administrative privileges to plant malicious scripts within the system. When other users or administrators view the affected pages, these scripts execute automatically in their web browsers. This could lead to unauthorized actions being performed on behalf of other users or the theft of sensitive session information.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in version 2.1 of the ITP Technology ITS Intelligent SCADA System. The flaw is caused by improper neutralization of user-supplied input during web page generation (CWE-79). A remote attacker with high privileges (PR:H) can inject malicious JavaScript into specific pages. This code is then persistently stored and executed in the context of any user's browser session when they navigate to the compromised page. Successful exploitation requires user interaction (UI:R) from the victim and can result in a limited impact on confidentiality and integrity within the application environment.

Affected products

  • ITP Technology ITS Intelligent SCADA System 2.1

Timeline

  • 2026-05-29: disclosed: Initial disclosure by TWCERT/CC
  • 2026-05-29: advisory: NVD publication date

References

Related threats