ScadaLTS 2.8.1-release-candidate build 0 存在一个经身份验证的远程代码执行漏洞,其根源在于脚本沙箱被绕过。 具体而言,DWR 框架中的 "DataSourceEditDwr" 类暴露了 "validateScript" 方法,该方法会通过 Rhino 脚本引擎编译并执行由攻击者提供的 JavaScript 代码。由于该方法未设置任何权限校验,拥有低权限账户访问权限的攻击者可以利用 DWR 路由绕过机制来滥用此缺陷,从而在服务器上执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84860 | 8.8 HIGH | Scada-LTS DWR Authorization Bypass - Systemic |
| CVE-2026-84859 | 6.5 MEDIUM | Scada-LTS Authenticated Blind SQL Injection |
No comments yet