← Vulnerability feed

Vulnerability record · CVE-2017-7282 · published 20 April 2017

CVE-2017-7282: Unitrends enterprise backup information exposure vulnerability

Unitrends · Enterprise Backup

An issue was discovered in Unitrends Enterprise Backup before 9.1.1. The function downloadFile in api/includes/restore.php blindly accepts any filename passed to /api/restore/download as valid. This allows an authenticated attacker to read any file in the filesystem that the web server has access to, aka Local File Inclusion (LFI).

5.5 CVSS 3.0 Medium EPSS 4.3% · top 9.2% CWE-200 · Information exposure
5.5CVSS 3.0 base score, v2 7.1
4.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Unitrends Enterprise Backup before 9.1.1. The function downloadFile in api/includes/restore.php blindly accepts any filename passed to /api/restore/download as valid. This allows an authenticated attacker to read any file in the filesystem that the web server has access to, aka Local File Inclusion (LFI).

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-7282 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2014-3008Unitrends enterprise backup os command injection vulnerabilityUnitrends Enterprise Backup 7.3.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the comm parameter to r…EPSS 7.0%9.8CVE-2017-7279Unitrends enterprise backup reliance on cookies without validation vulnerabilityAn unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" cookie issue…EPSS 4.4%9.8CVE-2017-7280Unitrends enterprise backup improper input validation vulnerabilityAn issue was discovered in api/includes/systems.php in Unitrends Enterprise Backup before 9.0.0. User input is not properly filtered before being sen…EPSS 6.2%8.8CVE-2017-7283Unitrends enterprise backup improper input validation vulnerabilityAn authenticated user of Unitrends Enterprise Backup before 9.1.2 can execute arbitrary OS commands by sending a specially crafted filename to the /a…EPSS 4.3%8.8CVE-2017-7281Unitrends enterprise backup unrestricted file upload vulnerabilityAn issue was discovered in Unitrends Enterprise Backup before 9.1.2. A lack of sanitization of user input in the createReportName and saveReport func…EPSS 4.3%8.8CVE-2017-7284Unitrends enterprise backup improper authentication vulnerabilityAn attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/users.php to change the passw…EPSS 2.7%7.5CVE-2014-3139Unitrends enterprise backup improper authentication vulnerabilityrecoveryconsole/bpl/snmpd.php in Unitrends Enterprise Backup 7.3.0 allows remote attackers to bypass authentication by setting the auth parameter to …EPSS 3.3%5.9CVE-2025-68686FortiOS symbolic link patch bypass exposes sensitive informationFortiOS contains an information exposure flaw (CWE-200) that lets a remote unauthenticated attacker bypass the patch for the symbolic link persistenc…KEVEPSS 30%analysed

Source: NIST National Vulnerability Database (record CVE-2017-7282), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.