Umbra Wiki cve cve/CVE-2018-7841
Back to wiki

CVE-2018-7841 — Schneider Electric U.motion Builder SQL Injection Vulnerability

provenance: imported · CVE: CVE-2018-7841

CVE-2018-7841: Schneider Electric U.motion Builder SQL Injection Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Schneider Electric
Product U.motion Builder
Date added 2022-04-15
Due date 2022-05-06
Ransomware campaign use Unknown

Description

A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered.

Required action (CISA)

The impacted product is end-of-life and should be disconnected if still in use.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2018-7841

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2018-7841
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog