CVE-2018-7766: SQL Injection
The vulnerability exists within processing of trackgetdata.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the id input parameter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Schneider Electric U.motion Builderto a version that resolves this vulnerability.Fixed in v1.3.4
Event History
Frequently Asked Questions
What is CVE-2018-7766?
CVE-2018-7766 is a vulnerability that exists within the processing of track_getdata.php in Schneider Electric U.motion Builder software versions prior to v1.3.4.
What is the impact of CVE-2018-7766?
The vulnerability allows for SQL injection on the id input parameter, which could lead to unauthorized access, data theft, and potential compromise of the affected system.
How can I determine if my system is affected by CVE-2018-7766?
If you are running Schneider Electric U.motion Builder software versions prior to v1.3.4, your system may be affected by CVE-2018-7766.
Is there a fix for CVE-2018-7766?
Yes, upgrading to Schneider Electric U.motion Builder software version 1.3.4 or higher fixes the vulnerability.
Where can I find more information about CVE-2018-7766?
You can find more information about CVE-2018-7766 on the Schneider Electric website at https://www.schneider-electric.com/en/download/document/SEVD-2018-095-01/