ZeroHour

CVE-2017-7973

CVSS 3.0
9.8 critical
EPSS
1%p72
Published
()
Modified
Description

A SQL injection vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated user can use calls to various paths allowing performance of arbitrary SQL commands against the underlying database.

Vendors
schneider-electric
Products
u.motion builder
Weakness
CWE-89
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.