CVE-2018-7776: Infoleak
The vulnerability exists within error.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. System information is returned to the attacker that contains sensitive data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Schneider Electric U.motion Builderto a version that resolves this vulnerability.Fixed in 1.3.4
Event History
Frequently Asked Questions
What is CVE-2018-7776?
CVE-2018-7776 is a vulnerability found in Schneider Electric U.motion Builder software versions prior to v1.3.4.
What is the severity of CVE-2018-7776?
CVE-2018-7776 has a severity rating of 4.3, which is considered medium.
How does CVE-2018-7776 impact Schneider Electric U.motion Builder?
CVE-2018-7776 exposes sensitive system information to attackers.
How can I fix CVE-2018-7776?
To fix CVE-2018-7776, you should update Schneider Electric U.motion Builder software to version 1.3.4 or later.
Where can I find more information about CVE-2018-7776?
You can find more information about CVE-2018-7776 at the following link: https://www.schneider-electric.com/en/download/document/SEVD-2018-095-01/