CVE-2018-7764: Path Traversal
The vulnerability exists within runscript.php applet in Schneider Electric U.motion Builder software versions prior to v1.3.4. There is a directory traversal vulnerability in the processing of the 's' parameter of the applet.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Schneider Electric U.motion Builder (runscript.php applet)to a version that resolves this vulnerability.Fixed in v1.3.4
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-7764.
What is the title of the vulnerability?
The title of the vulnerability is 'The vulnerability exists within runscript.php applet in Schneider Electric U.motion Builder software...'
What is the description of the vulnerability?
The vulnerability is a directory traversal vulnerability in the processing of the 's' parameter of the applet.
What software is affected by the vulnerability?
The Schneider Electric U.motion Builder software versions prior to v1.3.4 are affected.
What is the severity of the vulnerability?
The severity of the vulnerability is medium with a CVSS score of 4.3.
How can I fix the vulnerability?
Update the Schneider Electric U.motion Builder software to version 1.3.4 or later.
Where can I find more information about the vulnerability?
You can find more information about the vulnerability at the following link: [Schneider Electric Security Notification](https://www.schneider-electric.com/en/download/document/SEVD-2018-095-01/)
What is the CWE ID for the vulnerability?
The CWE ID for the vulnerability is CWE-22.