CVE-2018-7769: SQL Injection
The vulnerability exists within processing of xmlserver.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the id input parameter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Schneider Electric U.motion Builder (xmlserver.php)to a version that resolves this vulnerability.Fixed in v1.3.4
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2018-7769.
What is the severity of CVE-2018-7769?
The severity of CVE-2018-7769 is high with a CVSS score of 8.8.
Which software versions are affected by CVE-2018-7769?
Schneider Electric U.motion Builder software versions prior to v1.3.4 are affected by CVE-2018-7769.
What is the impact of CVE-2018-7769?
CVE-2018-7769 allows attackers to perform SQL injection on the id input parameter of xmlserver.php in Schneider Electric U.motion Builder software.
How can I fix CVE-2018-7769?
To fix CVE-2018-7769, upgrade to version 1.3.4 of Schneider Electric U.motion Builder software.