High severity8.8NVD Advisory· Published Apr 12, 2017· Updated Jun 17, 2026
CVE-2017-7281
CVE-2017-7281
Description
An issue was discovered in Unitrends Enterprise Backup before 9.1.2. A lack of sanitization of user input in the createReportName and saveReport functions in recoveryconsole/bpl/reports.php allows for an authenticated user to create a randomly named file on disk with a user-controlled extension, contents, and path, leading to remote code execution, aka Unrestricted File Upload.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1- rhinosecuritylabs.com/research/remote-code-execution-bug-hunting-chapter-1/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.