CVE-2018-7768: SQL Injection
Published Jul 3, 2018
·Updated
The vulnerability exists within processing of loadtemplate.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the tpl input parameter.
Affected Software
1 affected component
Schneider-electric U.motion Builder<1.3.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Schneider Electric U.motion Builder (loadtemplate.php)to a version that resolves this vulnerability.Fixed in v1.3.4
Event History
Jul 3, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Data Sourced
via NVD·02:29 PM
DescriptionSeverityWeaknessAffected Software