CVE-2018-7765
Schneider Electric u.motion_builder Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Record summary
CVE-2018-7765 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.
Description
The vulnerability exists within processing of track_import_export.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the object_id input parameter.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 4, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
u.motion_builderBrowse Schneider Electric / u.motion_builder | VulnCheck | Version data not supplied | |
| CVE List | U.motion Builder Software, all versions prior to v1.3.4 | affected | |
Nuclei templates
1ProjectDiscoveryHIGHSchneider Electric U.motion Builder - SQL InjectionCVSS 8.8
The vulnerability exists within processing of track_import_export.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying SQLite database query is subject to SQL injection on the object_id input parameter.
Impact
Attackers can execute arbitrary SQL commands, potentially leading to data theft, modification, or deletion.
Remediation
Update to version v1.3.4 or later.
Source: ProjectDiscovery