Executive brief
ScadaBR, an open-source software used for monitoring and controlling industrial processes (SCADA), is vulnerable to a security flaw in how it handles web addresses. An attacker could trick a user into clicking a malicious link, allowing the attacker to run unauthorized scripts in the user's browser. This could lead to the theft of login sessions or sensitive information displayed within the application.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in ScadaBR due to improper neutralization of script-related HTML tags within URL handling (CWE-80). The vulnerability is reachable over the network without authentication, though it requires user interaction (e.g., clicking a crafted link). Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized actions. As of the advisory date, the project appears to be unmaintained and no official patch is available.
Affected products
- ScadaBR ScadaBR
Timeline
- 2026-05-28: advisory: Initial release of Tenable Research Advisory TRA-2026-46
- 2026-05-28: disclosed: NVD publication date