schneider-electric u-motion-builder CVE-2018-7777 is a vulnerability in Schneider Electric U Motion Builder
Published on July 3, 2018

The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A remote, authenticated attacker can exploit this vulnerability by sending a crafted request to the target server.

NVD


Products Associated with CVE-2018-7777

Want to know whenever a new CVE is published for Schneider Electric U Motion Builder? stack.watch will email you.

 

Affected Versions

Schneider Electric SE U.Motion Version U.motion Builder Software, all versions prior to v1.3.4 is affected by CVE-2018-7777

Exploit Probability

EPSS
15.81%
Percentile
94.67%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.