← Vulnerability feed

Vulnerability record · CVE-2018-7841 · published 22 May 2019

CVE-2018-7841: Schneider Electric U.motion Builder SQL injection allows code execution

Schneider Electric · U.Motion Builder

U.motion Builder version 1.3.4 contains a SQL injection flaw (CWE-89) that can lead to unwanted code execution when an improper set of characters is entered. It is remotely reachable with no authentication or user interaction and carries a critical CVSS score of 9.8, making it a serious risk for any deployment still running this end-of-life product.

9.8 CVSS 3.1 Critical CISA KEV since 15 Apr 2022 EPSS 73% · top 0.6% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 7.5
73%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper set of characters is entered.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCritical CVSS 9.8, unauthenticated network-reachable code execution, confirmed KEV listing and very high EPSS probability make this an urgent risk, compounded by the product being end-of-life with no patch path.

What it is

U.motion Builder version 1.3.4 contains a SQL injection flaw (CWE-89) that can lead to unwanted code execution when an improper set of characters is entered. It is remotely reachable with no authentication or user interaction and carries a critical CVSS score of 9.8, making it a serious risk for any deployment still running this end-of-life product.

Impact

An unauthenticated attacker can inject SQL and achieve code execution, gaining full control over confidentiality, integrity and availability of the affected system. This can lead to complete compromise of the host running U.motion Builder.

Attack surface

The CVSS vector AV:N/AC:L/PR:N/UI:N indicates the flaw is reachable over the network with no privileges and no user interaction required. The description states the trigger is entering an improper set of characters, consistent with a remotely supplied input field.

Exploitation

CVE-2018-7841 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-04-15) and has an EPSS 30-day probability of 0.727 (99.4th percentile). Public exploit references exist on Packet Storm and the Full Disclosure mailing list, so active exploitation should be assumed.

What to do

  • Disconnect or retire U.motion Builder 1.3.4, which is end-of-life per CISA's required action; do not rely on patching since no supported fix is indicated.
  • If the product cannot be removed immediately, isolate it on a segmented network with strict firewall rules limiting access to trusted management hosts only.
  • Monitor vendor advisory SEVD-2019-071-02 for any updated guidance and apply it if a supported replacement or fix becomes available.
  • Inventory all instances of U.motion Builder across the environment and prioritize removal of any internet-facing or broadly reachable deployments.

Detection

  • Search web and application logs for SQL metacharacters (quotes, comment sequences, UNION, stacked queries) in requests to U.motion Builder endpoints.
  • Alert on unexpected child processes or command execution spawned by the U.motion Builder service, which would indicate successful code execution.
  • Monitor network traffic to and from U.motion Builder hosts for anomalous outbound connections or unusual request patterns from external sources.
  • Correlate IDS/IPS signatures for SQL injection and known exploit traffic against U.motion Builder hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-7841 to the Known Exploited Vulnerabilities catalog on 15 April 2022 as "Schneider Electric U.motion Builder SQL Injection Vulnerability". Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 6 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-7841 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-7785Schneider-electric u.motion builder command injection vulnerabilityIn Schneider Electric U.motion Builder software versions prior to v1.3.4, a remote command injection allows authentication bypass.EPSS 3.0%9.8CVE-2017-7973Schneider-electric u.motion builder sql injection vulnerabilityA SQL injection vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated user can …EPSS 1.5%9.8CVE-2017-7974Schneider-electric u.motion builder path traversal vulnerabilityA path traversal information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an u…EPSS 4.6%9.8CVE-2017-9957Schneider-electric u.motion builder hard-coded credentials vulnerabilityA vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the web service contains a hidden system a…EPSS 1.6%8.8CVE-2018-7774Schneider-electric u.motion builder sql injection vulnerabilityThe vulnerability exists within processing of localize.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underlying S…EPSS 0.97%8.8CVE-2018-7777Schneider-electric u.motion builder improper input validation vulnerabilityThe vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Electric U.motion Builder softwa…EPSS 32%8.8CVE-2018-7765Schneider-electric u.motion builder sql injection vulnerabilityThe vulnerability exists within processing of track_import_export.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The u…EPSS 2.9%8.8CVE-2018-7766Schneider-electric u.motion builder sql injection vulnerabilityThe vulnerability exists within processing of track_getdata.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. The underly…EPSS 0.97%

Source: NIST National Vulnerability Database (record CVE-2018-7841), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.