← KEV catalog
CISA known exploited vulnerability

CVE-2018-7841

Schneider Electric U.motion Builder SQL Injection Vulnerability

SOURCE FACT

Schneider Electric · U.motion Builder

A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered.

Required action

The impacted product is end-of-life and should be disconnected if still in use.

CISA notes

https://nvd.nist.gov/vuln/detail/CVE-2018-7841

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?