CVE-2018-7841 KEV EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 72.7% (pctl 99)
Patch first
On CISA KEV — known exploited in the wild, due 2022-05-06.
Description
A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper set of characters is entered.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 72.68% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | yes — remediate by 2022-05-06 |
| Public exploit | yes |
| Published | 2019-05-22 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Schneider Electric U.motion Builder SQL Injection Vulnerability |
|---|---|
| Added | 2022-04-15 |
| Due | 2022-05-06 |
| Vendor / product | Schneider Electric / U.motion Builder |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| schneider-electric | u.motion builder |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Schneider Electric U.Motion Builder 1.3.4 - 'track_import_export.php object_id' Unauthenticated Command Injection | 2019-05-14 |
References
- http://packetstormsecurity.com/files/152862/Schneider-Electric-U.Motion-Builder-1.3.4-Command-Injection.html
- http://seclists.org/fulldisclosure/2019/May/26
- https://www.schneider-electric.com/ww/en/download/document/SEVD-2019-071-02
- http://packetstormsecurity.com/files/152862/Schneider-Electric-U.Motion-Builder-1.3.4-Command-Injection.html
- http://seclists.org/fulldisclosure/2019/May/26
- https://www.schneider-electric.com/ww/en/download/document/SEVD-2019-071-02
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-7841
→ the Explorer · watch your stack · NVD