PT-2026-96050 · Scadabr · Scadabr
CVSS v4.0
5.5
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P |
Name of the Vulnerable Software and Affected Versions
ScadaBR versions prior to 1.2.0
Description
A remote information disclosure issue exists in the Export Project Endpoint component. The flaw is located in the
EmportDwr.createExportJSON() function within the /ScadaBR/export project.htm file. This occurs because the export path was left unprotected, unlike the import path which is restricted by the Permissions.ensureAdmin() function.Recommendations
Update to version 1.2.0.
Exploit
Fix
Improper Access Control
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Scadabr