SQL Injection Vulnerability in NetBotz by Schneider Electric
CVE-2026-13337
5.1MEDIUM
What is CVE-2026-13337?
A SQL injection vulnerability exists in the NetBotz products from Schneider Electric, allowing an authenticated attacker to inject malicious HQL queries into the database. This risk is present through access via the web service interface or web UI. Proper authentication and input validation mechanisms are crucial to mitigate this type of vulnerability and protect sensitive data within the application.
Affected Version(s)
NetBotz 5 - 750/755 Versions 5.5.2 and prior