CVE-2017-7973
25Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Attendepss 1.5%
from disclosure to weapon
Published on NVDSep 25
VulnCheck+3083d
exploitation probability
1.5%top 27% of all CVEs
observed exploitation
yesVulnCheck
A SQL injection vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated user can use calls to various paths allowing performance of arbitrary SQL commands against the underlying database.
Affected products
Schneider Electric SE · U.Motion