ZeroHour

CVE-2021-26829

KEV PoC niche

Cross-Site Scripting (XSS) in OpenPLC ScadaBR system_settings.shtm

CISA: OpenPLC ScadaBR Cross-site Scripting Vulnerability

CVSS 3.1
5.4 medium
EPSS
48%p99
Published
()
KEV added
AI analysis

OpenPLC ScadaBR, an open-source SCADA/HMI web application, contains a cross-site scripting flaw (CWE-79) in its system_settings.shtm settings page. An attacker can trigger it by getting a user's browser to load system_settings.shtm with malicious script injected into the request, which the application then renders without adequate sanitization. Successful exploitation executes attacker-supplied script in the victim's browser session, potentially hijacking the authenticated web session and performing actions such as changing settings or views as that user. Any organization running the OpenPLC ScadaBR web interface is affected, especially instances reachable from the internet or by untrusted users. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-11-28, indicating exploitation in the wild, and EPSS assigns a 48% probability of exploitation within 30 days (99th percentile); no public proof-of-concept is known and no CVSS score has been published.

What to do: Apply mitigations per vendor instructions and update ScadaBR/OpenPLC to the latest available build, since the advisory does not specify a fixed version; federal agencies must meet the BOD 22-01 deadline or discontinue use if mitigations are unavailable. Restrict network access to the ScadaBR web interface so it is not directly internet-exposed, and review web-server logs for suspicious or script-bearing requests to system_settings.shtm. Prioritize patching on internet-facing instances given the KEV listing and elevated EPSS score.

Affected
OpenPLC ScadaBR
Estimated exposure
nicheLikely hundreds to a few thousand ScadaBR instances worldwide (estimate; no published install base) — No vendor install base is published; ScadaBR is a niche open-source SCADA/HMI platform used mainly in small industrial, utility, and educational deployments, which public internet scans suggest gives it only a small internet-exposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.

CISA Known Exploited Vulnerability
Affected
OpenPLC ScadaBR
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
scadabr
Products
scadabr
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news