CVE-2018-7841: critical vulnerability in U.motion Builder software version 1.3.4
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
The impacted product is end-of-life and should be disconnected if still in use.
U.motion Builder 1.3.4 allows attackers to inject malicious SQL code through improper character input, potentially gaining unauthorized access to the database or executing arbitrary commands on the system.
SQL Injection vulnerability in U.motion Builder 1.3.4 allows remote attackers to execute arbitrary SQL queries by crafting specially-formatted input that bypasses input validation, enabling unauthorized database access, data exfiltration, or code execution depending on database permissions and application context.
The full analysis of this CVE is available in Portuguese →