SOURCE FACT
Schneider Electric · U.motion Builder
A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered.
Required action
The impacted product is end-of-life and should be disconnected if still in use.
CISA notes
https://nvd.nist.gov/vuln/detail/CVE-2018-7841
View source evidence →