CRITICAL🇵🇱 Wersja polska

CVE-2017-7973

CVSS 9.8v3.0pub. 2017-09-26upd. 2026-05-13

A SQL injection vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated user can use calls to various paths allowing performance of arbitrary SQL commands against the underlying database.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Schneider Electric U.motion Builder

    APP
    Schneider-Electric
    ≤ 1.2.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2018-7841CRITICAL9.8⚠ KEVPL ✓same product

SQL Injection z RCE w Schneider Electric U.Motion Builder 1.3.4

CVE-2018-7785CRITICAL9.8PL ✓same product

Command injection z pominięciem uwierzytelnienia w Schneider Electric U.Motion Builder

CVE-2017-9957CRITICAL9.8PL ✓same product

Schneider Electric U.Motion Builder — ukryte konto z hardcoded hasłem

CVE-2017-7974CRITICAL9.8PL ✓same product

Path Traversal i RCE w Schneider Electric U.Motion Builder

CVE-2018-7765HIGH8.8same product

The vulnerability exists within processing of track_import_export.php in Schneider Electric U.motion Builder s...