CVE-2017-7283: Unitrends Enterprise Backup
High severity, CVSS 8.8. EPSS: 4.3% chance of exploitation in the next 30 days.
An authenticated user of Unitrends Enterprise Backup before 9.1.2 can execute arbitrary OS commands by sending a specially crafted filename to the /api/restore/download-files endpoint, related to the downloadFiles function in api/includes/restore.php.
Affected products
- Unitrends Enterprise Backup: up to and including 9.1.1
Published 2017-04-20. Last modified 2026-06-17.