First published: Tue Jul 03 2018(Updated: )
The vulnerability exists within processing of xmlserver.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the id input parameter.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric U.motion Builder | <1.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2018-7769.
The severity of CVE-2018-7769 is high with a CVSS score of 8.8.
Schneider Electric U.motion Builder software versions prior to v1.3.4 are affected by CVE-2018-7769.
CVE-2018-7769 allows attackers to perform SQL injection on the id input parameter of xmlserver.php in Schneider Electric U.motion Builder software.
To fix CVE-2018-7769, upgrade to version 1.3.4 of Schneider Electric U.motion Builder software.