CVE-2018-7773: SQL Injection
The vulnerability exists within processing of nfcserver.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the sessionid input parameter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Schneider Electric U.motion Builderto a version that resolves this vulnerability.Fixed in v1.3.4
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2018-7773.
What software versions are affected by this vulnerability?
The vulnerability affects Schneider Electric U.motion Builder software versions prior to v1.3.4.
What is the severity of CVE-2018-7773?
The severity of CVE-2018-7773 is high with a CVSS score of 8.8.
What is the nature of the vulnerability in Schneider Electric U.motion Builder?
The vulnerability in Schneider Electric U.motion Builder is a SQL injection vulnerability in the nfcserver.php file.
How can I fix CVE-2018-7773?
To fix CVE-2018-7773, you should update Schneider Electric U.motion Builder to version 1.3.4 or later.