CVE-2018-7841
Schneider Electric U.motion Builder SQL Injection Vulnerability
- Published
- May 22, 2019
- Updated
- Oct 21, 2025
- Assigning CNA
- schneider
- Evidence observed
- May 14, 2019
Schneider Electric U.motion Builder SQL Injection Vulnerability
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper set of characters is entered.
Julien Ahrens · php · May 14, 2019
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.