First published: Tue Jul 03 2018(Updated: )
The vulnerability exists within css.inc.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The 'css' parameter contains a directory traversal vulnerability.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric U.motion Builder | <1.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-7763.
The affected software is Schneider Electric U.motion Builder versions prior to v1.3.4.
The severity of CVE-2018-7763 is medium with a severity value of 4.3.
To fix CVE-2018-7763, update Schneider Electric U.motion Builder software to v1.3.4 or above.
You can find more information about CVE-2018-7763 at the following link: [Schneider Electric Security Advisory SEVD-2018-095-01](https://www.schneider-electric.com/en/download/document/SEVD-2018-095-01/)