CVE-2017-7973

A SQL injection vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated user can use calls to various paths allowing performance of arbitrary SQL commands against the underlying database.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:schneider-electric:u.motion_builder:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-09-26 01:29

Updated : 2023-12-10 12:15


NVD link : CVE-2017-7973

Mitre link : CVE-2017-7973

CVE.ORG link : CVE-2017-7973


JSON object : View

Products Affected

schneider-electric

  • u.motion_builder
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')