CVE-2021-26829
Last modified
CVE-2021-26829 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.. CISA has confirmed active exploitation in the wild. EPSS estimates a 48.05% chance of exploitation in the next 30 days.
Description
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Scadabr | Scadabr | <= 0.9.1 |
| Scadabr | Scadabr | <= 1.12.4 |
References
- https://youtu.be/Xh6LPCiLMa8Exploit, Third Party Advisory
- https://youtu.be/Xh6LPCiLMa8Exploit, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-26829US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2021-26829?
How severe is CVE-2021-26829?
How do I fix CVE-2021-26829?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-26822Teachers Record Management System 1.0 is affected by a SQL i…9.8
- CVE-2021-26824DM FingerTool v1.19 in the DM PD065 Secure USB is susceptibl…7.1
- CVE-2021-26825An integer overflow issue exists in Godot Engine up to v3.2 …7.8
- CVE-2021-26826A stack overflow issue exists in Godot Engine up to v3.2 and…7.8
- CVE-2021-26827Buffer Overflow in TP-Link WR2041 v1 firmware for the TL-WR2…7.5
- CVE-2021-26828OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on…8.8
- CVE-2021-26830SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows …9.1
- CVE-2021-26832Cross Site Scripting (XSS) in the "Reset Password" page form…6.1
- CVE-2021-26833Cleartext Storage in a File or on Disk in TimelyBills <= 1.7…5.9
- CVE-2021-26834A cross-site scripting (XSS) vulnerability exists in Znote 0…5.4
- CVE-2021-26835No filtering of cross-site scripting (XSS) payloads in the m…6.1
- CVE-2021-26837SQL Injection vulnerability in SearchTextBox parameter in Fo…9.8
Are you affected by CVE-2021-26829?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
