First published: Tue Jul 03 2018(Updated: )
The vulnerability exists within processing of editscript.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A directory traversal vulnerability allows a caller with standard user privileges to write arbitrary php files anywhere in the web service directory tree.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric U.motion Builder | <1.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2018-7771.
The title of this vulnerability is 'The vulnerability exists within processing of editscript.php in Schneider Electric U.motion Builder software versions prior to v1.3.4.'
The description of this vulnerability is 'A directory traversal vulnerability allows a caller with standard user privileges to write arbitrary PHP files anywhere in the web service directory tree.'
The affected software for this vulnerability is Schneider Electric U.motion Builder software versions prior to v1.3.4.
The severity of this vulnerability is high with a severity value of 8.
To fix this vulnerability, update Schneider Electric U.motion Builder software to version 1.3.4 or higher.