Scadabr: community verdicts
2 notable / known-exploited Scadabr CVEs the community has triaged.
ⓘ Not an exhaustive list: we focus on the findings that matter (exploited / notable). For every Scadabr CVE, see NVD ↗.
- CVE-2021-26829MED 5.4KEVEPSS 48%
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.
- CVE-2021-26828HIGH 8.8KEVEPSS 39%
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.