CVE-2018-7763: Path Traversal
The vulnerability exists within css.inc.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The 'css' parameter contains a directory traversal vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Schneider Electric U.motion Builderto a version that resolves this vulnerability.Fixed in v1.3.4
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID for this issue is CVE-2018-7763.
What is the affected software?
The affected software is Schneider Electric U.motion Builder versions prior to v1.3.4.
What is the severity of CVE-2018-7763?
The severity of CVE-2018-7763 is medium with a severity value of 4.3.
How can I fix CVE-2018-7763?
To fix CVE-2018-7763, update Schneider Electric U.motion Builder software to v1.3.4 or above.
Where can I find more information about CVE-2018-7763?
You can find more information about CVE-2018-7763 at the following link: [Schneider Electric Security Advisory SEVD-2018-095-01](https://www.schneider-electric.com/en/download/document/SEVD-2018-095-01/)