IM
IronMonkey Threat Research

CVE-2018-7763 MEDIUM

Published: 2018-07-03 | Last Modified: 2026-06-17 | Status: Modified

Description

The vulnerability exists within css.inc.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The 'css' parameter contains a directory traversal vulnerability.

Additional Descriptions (1)

Existe una vulnerabilidad en css.inc.php en el software de Schneider Electric U.motion Builder en versiones anteriores a la v1.3.4. El parĂ¡metro "css" contiene una vulnerabilidad de salto de directorio.

CVSS Metrics

Base Score: 4.3 (MEDIUM)

AV:N/AC:M/Au:N/C:P/I:N/A:N

Access VectorNETWORK
Access ComplexityMEDIUM
AuthenticationNONE
Confidentiality ImpactPARTIAL
Integrity ImpactNONE
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 8.6

Impact Score: 2.9

Weaknesses

Source Type Description
[email protected] Primary
en CWE-22

Affected Products

Vendor Product Version Update Type
schneider-electric u.motion_builder * <built-in method update of dict object at 0x7e60eb2e15c0> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:schneider-electric:u.motion_builder:*:*:*:*:*:*:*:*
Notification
Message here