CVE-2018-7765: SQL Injection
The vulnerability exists within processing of trackimportexport.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the objectid input parameter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Schneider Electric U.motion Builderto a version that resolves this vulnerability.Fixed in v1.3.4
Event History
Frequently Asked Questions
What is CVE-2018-7765?
CVE-2018-7765 is a vulnerability that exists within the processing of track_import_export.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the object_id input parameter.
What software is affected by CVE-2018-7765?
Schneider Electric U.motion Builder software versions prior to v1.3.4 are affected by CVE-2018-7765.
What is the severity of CVE-2018-7765?
CVE-2018-7765 has a severity rating of high, with a CVSS score of 8.8.
How can I fix CVE-2018-7765?
To fix CVE-2018-7765, it is recommended to upgrade Schneider Electric U.motion Builder software to version 1.3.4 or later.
Where can I find more information about CVE-2018-7765?
More information about CVE-2018-7765 can be found in the following references: - [http://seclists.org/fulldisclosure/2019/May/26](http://seclists.org/fulldisclosure/2019/May/26) - [https://www.schneider-electric.com/en/download/document/SEVD-2018-095-01/](https://www.schneider-electric.com/en/download/document/SEVD-2018-095-01/)