CVE

Id
104104  
CVE No.
CVE-2017-7284  
Status
Candidate  
Description
An attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/users.php to change the password of the logged in account without knowing the current password. This allows for an account takeover.  
Phase
Assigned (20170327)  
Votes
None (candidate not yet proposed)  
Comments