OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability
OpenPLC · ScadaBR
Date added (CISA)
2025-12-03
Remediation due
2025-12-24
Known ransomware use
Not indicated
Remediation priority
P2 — past CISA due date
Description
OpenPLC ScadaBR contains an unrestricted upload of file with dangerous type vulnerability that allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.