First published: Wed May 22 2019(Updated: )
A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper set of characters is entered.
Credit: cybersecurity@se.com cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric U.motion Builder | =1.3.4 | |
Schneider Electric U.motion Builder | ||
=1.3.4 |
The impacted product is end-of-life and should be disconnected if still in use.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7841 is a SQL Injection vulnerability that exists in U.motion Builder software version 1.3.4.
CVE-2018-7841 has a severity score of 9.8 (Critical).
CVE-2018-7841 could allow an attacker to execute unwanted code by entering an improper set of characters.
To fix CVE-2018-7841, it is recommended to update U.motion Builder software to version 1.4 or later.
You can find more information about CVE-2018-7841 in the references provided: [link1], [link2], [link3].