CVE-2018-7770

The vulnerability exists within processing of sendmail.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The applet allows callers to select arbitrary files to send to an arbitrary email address.
Configurations

Configuration 1 (hide)

cpe:2.3:a:schneider-electric:u.motion:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:12

Type Values Removed Values Added
References () https://www.schneider-electric.com/en/download/document/SEVD-2018-095-01/ - Vendor Advisory () https://www.schneider-electric.com/en/download/document/SEVD-2018-095-01/ - Vendor Advisory

Information

Published : 2018-07-03 14:29

Updated : 2024-11-21 04:12


NVD link : CVE-2018-7770

Mitre link : CVE-2018-7770

CVE.ORG link : CVE-2018-7770


JSON object : View

Products Affected

schneider-electric

  • u.motion
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')