CVE-2018-7767: SQL Injection
The vulnerability exists within processing of editobject.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the type input parameter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Schneider Electric U.motion Builderto a version that resolves this vulnerability.Fixed in v1.3.4
Event History
Frequently Asked Questions
What is the overview of CVE-2018-7767 vulnerability?
The vulnerability exists within processing of editobject.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the type input parameter.
What is the severity of CVE-2018-7767?
CVE-2018-7767 has a severity value of 8.8 (high).
Which software versions are affected by CVE-2018-7767?
Schneider Electric U.motion Builder software versions prior to v1.3.4 are affected by CVE-2018-7767.
How can I fix CVE-2018-7767?
To fix CVE-2018-7767, it is recommended to update Schneider Electric U.motion Builder software to version 1.3.4 or later.
Where can I find more information about CVE-2018-7767?
You can find more information about CVE-2018-7767 at the following link: [Schneider Electric Security Advisory SEVD-2018-095-01](https://www.schneider-electric.com/en/download/document/SEVD-2018-095-01/).