Junglewise Threat Intelligence

CVE-2018-7841: Schneider Electric U.motion Builder SQL Injection Vulnerability

CVE-2018-7841 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-04-15

Vendors: Schneider Electric.

Executive brief

A SQL Injection vulnerability in Schneider Electric U.motion Builder version 1.3.4 allows a remote attacker to execute arbitrary code by entering an improper set of characters. The vulnerability is caused by improper neutralization of special elements used in an SQL command (CWE-89).

Affected products

  • Schneider Electric U.motion Builder 1.3.4

Timeline

  • 2019-03-12: advisory: Vendor advisory SEVD-2019-071-02 published
  • 2019-05-22: disclosed: NVD Published Date
  • 2022-04-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-04-15: exploited: CISA confirms exploitation in the wild