CVE-2018-7841criticalunder attackCWE-89

CVE-2018-7841: critical vulnerability in U.motion Builder software version 1.3.4

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 73%
from disclosure to weapon0 days
Published on NVDMay 22
1st PoCMay 14
CISA KEV+1059d
exploitation probability
73%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
2 public exploit(s)
Action required by CISAfederal deadline: 2022-05-06

The impacted product is end-of-life and should be disconnected if still in use.

In short

U.motion Builder 1.3.4 allows attackers to inject malicious SQL code through improper character input, potentially gaining unauthorized access to the database or executing arbitrary commands on the system.

Technical detail

SQL Injection vulnerability in U.motion Builder 1.3.4 allows remote attackers to execute arbitrary SQL queries by crafting specially-formatted input that bypasses input validation, enabling unauthorized database access, data exfiltration, or code execution depending on database permissions and application context.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper set of characters is entered.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.