CVE-2018-7841
CRITICAL KEV NUCLEIU.motion Builder <1.3.4 - SQL Injection
Title source: llmDescription
A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper set of characters is entered.
Exploits (1)
Nuclei Templates (1)
Schneider Electric U.motion Builder - Remote Code Execution
CRITICALVERIFIEDby darses,rcesecurity
Shodan:
http.headers_hash:1985490094
References (4)
Scores
CVSS v3
9.8
EPSS
0.5474
EPSS Percentile
98.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2022-04-15
VulnCheck KEV
2019-06-06
InTheWild.io
2022-04-15
ENISA EUVD
EUVD-2018-19553
CWE
CWE-89
Status
published
Products (1)
schneider-electric/u.motion_builder
1.3.4
Published
May 22, 2019
KEV Added
Apr 15, 2022
Tracked Since
Feb 18, 2026