CVE-2017-7974

A path traversal information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated user can execute arbitrary code and exfiltrate files.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:schneider-electric:u.motion_builder:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-09-26 01:29

Updated : 2023-12-10 12:15


NVD link : CVE-2017-7974

Mitre link : CVE-2017-7974

CVE.ORG link : CVE-2017-7974


JSON object : View

Products Affected

schneider-electric

  • u.motion_builder
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')