CISA Known Exploited Vulnerability

CVE-2018-7841

Schneider Electric · U.motion Builder

Schneider Electric U.motion Builder SQL Injection Vulnerability

Date added
BOD 22-01 due date
CWE CWE-89
Ransomware Unknown

CISA description

A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered.

Required action

The impacted product is end-of-life and should be disconnected if still in use.