A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper set of characters is entered.
https://www.schneider-electric.com/ww/en/download/document/SEVD-2019-071-02
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-7841