ZeroHour

CVE-2018-7787

CVSS 3.0
5.3 medium
EPSS
1%p63
Published
()
Modified
Description

In Schneider Electric U.motion Builder software versions prior to v1.3.4, this vulnerability is due to improper validation of input of context parameter in HTTP GET request.

Vendors
schneider-electric
Products
u.motion builder
Weakness
CWE-20
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news