CVE-2018-7841

CRITICAL KEV NUCLEI

U.motion Builder <1.3.4 - SQL Injection

Title source: llm

Description

A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper set of characters is entered.

Exploits (1)

exploitdb WORKING POC
by Julien Ahrens · textwebappsphp
https://www.exploit-db.com/exploits/46846

Nuclei Templates (1)

Schneider Electric U.motion Builder - Remote Code Execution
CRITICALVERIFIEDby darses,rcesecurity
Shodan: http.headers_hash:1985490094

Scores

CVSS v3 9.8
EPSS 0.5474
EPSS Percentile 98.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2022-04-15
VulnCheck KEV 2019-06-06
InTheWild.io 2022-04-15
ENISA EUVD EUVD-2018-19553
CWE
CWE-89
Status published
Products (1)
schneider-electric/u.motion_builder 1.3.4
Published May 22, 2019
KEV Added Apr 15, 2022
Tracked Since Feb 18, 2026