Schneider.Electric.U.motion.Builder.SQL.Injection

description-logoDescription

This indicates an attack attempt against a Command Injection vulnerability in Schneider Electric U.motion Builder.
The vulnerability is due to insufficient validation of user supplied inputs. A remote attacker can exploit this by sending a crafted query to execute SQL commands on a vulnerable server.

affected-products-logoAffected Products

Schneider Electric U.motion Builder 1.3.4 and prior

Impact logoImpact

System Compromise: Remote attackers can add, view, delete or modify data in the database of the affected application

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Status Detail
2026-03-17 35.185
Modified
Status:evaluate:enabled
2026-03-10 35.181
Modified
Status:enabled:evaluate