CVE-2017-7283

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
20/04/2017
Last modified:
20/04/2025

Description

An authenticated user of Unitrends Enterprise Backup before 9.1.2 can execute arbitrary OS commands by sending a specially crafted filename to the /api/restore/download-files endpoint, related to the downloadFiles function in api/includes/restore.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:unitrends:enterprise_backup:*:*:*:*:*:*:*:* 9.1.1 (including)