# Unitrends Enterprise Backup Privilege Escalation in users.php File  \[CVE-2017-7284\]

## Vulnerability Details

CVSS Rating: 8.8 (high)

### CVE-2017-7284

**Disclosing Company:** Rhino Security Labs  
**Date:** 04/12/2017  
**Status:** Published  
**Affected software/version:**  
Unitrends Enterprise Backup < 9.1.2

## Disclosure

### Rhino Security Labs References

[Blog Post: "Unitrends Vulnerability Hunting: Remote Code Execution"](/content/research/remote-code-execution-bug-hunting-chapter-1/index.html)

[GitHub: Remote Password Change Exploit](https://github.com/RhinoSecurityLabs/Security-Research/tree/master/exploits/Unitrends/CVE-2017-7284-Remote-Password-Change)

[Unitrends: Unitrends forced password change in users.php](https://support.unitrends.com/UnitrendsBackup/s/article/000005553)

[MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7284)

[NIST](https://nvd.nist.gov/vuln/detail/CVE-2017-7284)

### Disclosure Date

04/12/2017

### Vulnerability Description

An attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/users.php to change the password of the logged in account without knowing the current password. This allows for an account takeover.

### Related Disclosures

[Unitrends Enterprise Backup Local File Inclusion\[CVE-2017-7282\]](/content/vulnerability-disclosure/unitrends-enterprise-backup-local-file-inclusion/index.html)

[Unitrends Enterprise Backup Privilege Escalation in Token Cookie\[CVE-2017-7279\]](/content/vulnerability-disclosure/unitrends-enterprise-backup-privilege-escalation-in-token-cookie/index.html)

[Unitrends Enterprise Backup Remote Code Execution in systems.php File\[CVE-2017-7280\]](/content/vulnerability-disclosure/unitrends-enterprise-backup-remote-code-execution-in-systems-php-file/index.html)

[Unitrends Enterprise Backup Remote Code Execution in reports.php File\[CVE-2017-7281\]](/content/vulnerability-disclosure/unitrends-enterprise-backup-remote-code-execution-in-reports-php-file/index.html)

[Unitrends Enterprise Backup Remote Code Execution in restore.php File\[CVE-2017-7283\]](/content/vulnerability-disclosure/unitrends-enterprise-backup-remote-code-execution-in-restore-php-file/index.html)

## CVSS Metrics

### CVSS Rating (version 3.0)

**8.8 (High)**

### Impact Score

### Exploitability Score

5.9

2.8

### Attack Vector

Network

**Attack Complexity (AC)** Low  
**Privileges Required (PR)** Low  
**User Interaction (UI)** None  
**Scope (S)** Unchanged

**Confidentiality (C)** High  
**Integrity (I)** High  
**Availability (A)** High
