Executive brief
A SQL Injection vulnerability in Schneider Electric U.motion Builder version 1.3.4 allows a remote attacker to execute arbitrary code by entering an improper set of characters. The vulnerability is caused by improper neutralization of special elements used in an SQL command (CWE-89).
Affected products
- Schneider Electric U.motion Builder 1.3.4
Timeline
- 2019-03-12: advisory: Vendor advisory SEVD-2019-071-02 published
- 2019-05-22: disclosed: NVD Published Date
- 2022-04-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-04-15: exploited: CISA confirms exploitation in the wild