{ "schema_version": "1.4.0", "id": "GHSA-j87g-5g8x-jjxc", "modified": "2022-05-24T19:05:12Z", "published": "2022-05-24T19:05:12Z", "aliases": [ "CVE-2021-26828" ], "details": "OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-26828" }, { "type": "WEB", "url": "https://youtu.be/k1teIStQr1A" }, { "type": "WEB", "url": "http://forum.scadabr.com.br/t/report-falhas-de-seguranca-em-versoes-do-scadabr/3615/4" }, { "type": "WEB", "url": "http://packetstormsecurity.com/files/162564/ScadaBR-1.0-1.1CE-Linux-Shell-Upload.html" } ], "database_specific": { "cwe_ids": [ "CWE-434" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2021-06-11T12:15:00Z" } }