ScadaLTS 2.8.1-release-candidate(构建 0)存在经过身份验证的盲 SQL 注入漏洞。 端点接受一个包含 数组的 JSON 请求体。该数组中的值被直接拼接进 SQL 的 子句,未进行任何净化或参数化处理。这使得拥有 角色的经过身份验证的用户能够执行基于时间和布尔值的盲 SQL 注入,从而从数据库中提取任意数据,包括所有用户的密码哈希值。 根据 中的定义,该端点对拥有 、 或 角色的任何经过身份验证的用户均可通过 访问。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84858 | 8.8 HIGH | Scada-LTS Authenticated Remote Code Execution via Scripting Sandbox Bypass |
| CVE-2026-84860 | 8.8 HIGH | Scada-LTS DWR Authorization Bypass - Systemic |
No comments yet