Loading vulnerability details…
CVSS v3.1
N/A
EPSS
4.39%
Published
Apr 12, 2017
Modified
May 12, 2026
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" cookie issued at login.
Weaknesses (CWE)
Affected Products (1)
References (2)