A path traversal information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated user can execute arbitrary code and exfiltrate files.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSchneider Electric U.motion Builder
APPSchneider-Electric≤ 1.2.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEPath Traversal
CWE
Related vulnerabilities
CVE-2018-7841CRITICAL9.8⚠ KEVPL ✓same product
SQL Injection z RCE w Schneider Electric U.Motion Builder 1.3.4
CVE-2018-7785CRITICAL9.8PL ✓same product
Command injection z pominięciem uwierzytelnienia w Schneider Electric U.Motion Builder
CVE-2017-9957CRITICAL9.8PL ✓same product
Schneider Electric U.Motion Builder — ukryte konto z hardcoded hasłem
CVE-2017-7973CRITICAL9.8PL ✓same product
SQL injection w Schneider Electric U.Motion Builder – dostęp bez uwierzytelnienia
CVE-2018-7765HIGH8.8same product
The vulnerability exists within processing of track_import_export.php in Schneider Electric U.motion Builder s...