CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.8. Exploitation may require the attacker to be authenticated.
CVE
CVE-2017-7283
Severity
HIGH
CVSS
8.8
EPSS
4.28%
Original NVD Description
An authenticated user of Unitrends Enterprise Backup before 9.1.2 can execute arbitrary OS commands by sending a specially crafted filename to the /api/restore/download-files endpoint, related to the downloadFiles function in api/includes/restore.php.
Related CVEs
Other vulnerabilities affecting the same vendor(s)