CRITICAL🇵🇱 Wersja polska

CVE-2017-7974

CVSS 9.8v3.0pub. 2017-09-26upd. 2026-05-13

A path traversal information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated user can execute arbitrary code and exfiltrate files.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Schneider Electric U.motion Builder

    APP
    Schneider-Electric
    ≤ 1.2.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEPath Traversal
CWE
References

Related vulnerabilities

CVE-2018-7841CRITICAL9.8⚠ KEVPL ✓same product

SQL Injection z RCE w Schneider Electric U.Motion Builder 1.3.4

CVE-2018-7785CRITICAL9.8PL ✓same product

Command injection z pominięciem uwierzytelnienia w Schneider Electric U.Motion Builder

CVE-2017-9957CRITICAL9.8PL ✓same product

Schneider Electric U.Motion Builder — ukryte konto z hardcoded hasłem

CVE-2017-7973CRITICAL9.8PL ✓same product

SQL injection w Schneider Electric U.Motion Builder – dostęp bez uwierzytelnienia

CVE-2018-7765HIGH8.8same product

The vulnerability exists within processing of track_import_export.php in Schneider Electric U.motion Builder s...