CVE-2018-7777: Input Validation
The vulnerability is due to insufficient handling of updatefile request parameter on updatemodule.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A remote, authenticated attacker can exploit this vulnerability by sending a crafted request to the target server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Schneider Electric U.motion Builder (update_module.php)to a version that resolves this vulnerability.Fixed in v1.3.4
Event History
Frequently Asked Questions
What is CVE-2018-7777?
CVE-2018-7777 is a vulnerability in Schneider Electric U.motion Builder software versions prior to v1.3.4 that allows a remote, authenticated attacker to execute arbitrary commands.
How does CVE-2018-7777 occur?
CVE-2018-7777 occurs due to insufficient handling of the update_file request parameter on update_module.php in Schneider Electric U.motion Builder software versions prior to v1.3.4.
What is the severity of CVE-2018-7777?
CVE-2018-7777 has a severity rating of 8.8 out of 10 (high severity).
How can CVE-2018-7777 be exploited?
CVE-2018-7777 can be exploited by a remote, authenticated attacker by sending a crafted request to the target server.
How can I fix CVE-2018-7777?
To fix CVE-2018-7777, it is recommended to update Schneider Electric U.motion Builder software to version v1.3.4 or above.