CyberICT

CVE-2021-26828

OpenPLC · Published June 11, 2021

CVSS v3.1

HIGH
Patch availableGet patch

Description

OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.

Affected Products

  • Scadabr <= 0.9.1
  • Scadabr <= 1.12.4

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H