First published: Thu May 31 2018(Updated: )
In Schneider Electric U.motion Builder software versions prior to v1.3.4, this vulnerability is due to improper validation of input of context parameter in HTTP GET request.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric U.motion Builder | <1.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-7787.
The severity of CVE-2018-7787 is medium with a severity value of 5.3.
The affected software for CVE-2018-7787 is Schneider Electric U.motion Builder software versions prior to v1.3.4.
The CWE ID for CVE-2018-7787 is CWE-20.
To fix CVE-2018-7787, update Schneider Electric U.motion Builder software to version 1.3.4 or later.