634
VMScore

CVE-2017-7282

Published: 20/04/2017 Updated: 25/04/2017
CVSS v2 Base Score: 7.1 | Impact Score: 6.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 634
Vector: AV:N/AC:M/Au:N/C:C/I:N/A:N

Vulnerability Summary

An issue exists in Unitrends Enterprise Backup prior to 9.1.1. The function downloadFile in api/includes/restore.php blindly accepts any filename passed to /api/restore/download as valid. This allows an authenticated malicious user to read any file in the filesystem that the web server has access to, aka Local File Inclusion (LFI).

Vulnerable Product Search on Vulmon Subscribe to Product

unitrends enterprise backup