CVE-2017-7284
12.04.2017, 22:59
An attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/users.php to change the password of the logged in account without knowing the current password. This allows for an account takeover.Enginsight
Vendor | Product | Version |
---|---|---|
unitrends | enterprise_backup | 𝑥 ≤ 9.1.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration