CVE-2017-7284
An attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/users.php to change the password of the logged in account without knowing the current password. This allows for an account takeover.
- Affected products
- Unitrends Enterprise Backup
- Unitrends Enterprise Backup
- ≤ 9.1.1
- Fix
- Available
- CVSS 3.0
- 8.8 HIGH
- EPSS
- 2.2% (81th percentile)
- Weakness
- CWE-287
- NVD status
- Modified
- Published
- 2017-04-12
CVE-2017-7284 at NVD
1 known exploit for CVE-2017-7284
Proof-of-concept code and exploit modules indexed by Sploitus