CVE-2018-7771: Path Traversal
The vulnerability exists within processing of editscript.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A directory traversal vulnerability allows a caller with standard user privileges to write arbitrary php files anywhere in the web service directory tree.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Schneider Electric U.motion Builder (editscript.php)to a version that resolves this vulnerability.Fixed in v1.3.4
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-7771.
What is the title of this vulnerability?
The title of this vulnerability is 'The vulnerability exists within processing of editscript.php in Schneider Electric U.motion Builder software versions prior to v1.3.4.'
What is the description of this vulnerability?
The description of this vulnerability is 'A directory traversal vulnerability allows a caller with standard user privileges to write arbitrary PHP files anywhere in the web service directory tree.'
What is the affected software for this vulnerability?
The affected software for this vulnerability is Schneider Electric U.motion Builder software versions prior to v1.3.4.
What is the severity of this vulnerability?
The severity of this vulnerability is high with a severity value of 8.
How can I fix this vulnerability?
To fix this vulnerability, update Schneider Electric U.motion Builder software to version 1.3.4 or higher.