schneider-electric u-motion-builder CVE-2018-7771 is a vulnerability in Schneider Electric U Motion Builder
Published on July 3, 2018

The vulnerability exists within processing of editscript.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A directory traversal vulnerability allows a caller with standard user privileges to write arbitrary php files anywhere in the web service directory tree.

NVD


Products Associated with CVE-2018-7771

Want to know whenever a new CVE is published for Schneider Electric U Motion Builder? stack.watch will email you.

 

Affected Versions

Schneider Electric SE U.Motion Version U.motion Builder Software, all versions prior to v1.3.4 is affected by CVE-2018-7771

Exploit Probability

EPSS
0.46%
Percentile
63.79%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.