Loading
OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.
Use CWE-434, Scadabr vendor hub and Scadabr product page to widen CVE-2021-26828 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-26829, CVE-2019-16344 and CVE-2019-16321 for nearby disclosures in the same product family.