CVE Database · CVE-2017-7973
CVSS v3.1
N/A
EPSS
1.47%
Published
Sep 25, 2017
Modified
May 12, 2026
Public PoC / Exploit
All weaponized →No public PoC or exploit code indexed for this CVE.
Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
A SQL injection vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated user can use calls to various paths allowing performance of arbitrary SQL commands against the underlying database.
Weaknesses (CWE)
Affected Products (1)
References (4)