A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper set of characters is entered.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSchneider Electric U.motion Builder
APPSchneider-Electric1.3.4
CISA KEV — detailsi
- Vendori
- Schneider Electric
- Producti
- U.motion Builder
- Added to KEVi
- April 15, 2022
- Remediation deadline (US Federal)i
- May 6, 2022(overdue)
The impacted product is end-of-life and should be disconnected if still in use.
A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered.
Related vulnerabilities
Command injection z pominięciem uwierzytelnienia w Schneider Electric U.Motion Builder
SQL injection w Schneider Electric U.Motion Builder – dostęp bez uwierzytelnienia
Schneider Electric U.Motion Builder — ukryte konto z hardcoded hasłem
Path Traversal i RCE w Schneider Electric U.Motion Builder
The vulnerability exists within processing of track_import_export.php in Schneider Electric U.motion Builder s...