In Schneider Electric U.motion Builder software versions prior to v1.3.4, this vulnerability is due to improper validation of input of context parameter in HTTP GET request.
[
{
"product": "U.motion Builder",
"vendor": "Schneider Electric SE",
"versions": [
{
"status": "affected",
"version": "U.motion Builder, all versions prior to 1.3.4"
}
]
}
]