ZeroHour

CVE-2020-8427

CVSS 3.1
9.8 critical
EPSS
2%p73
Published
()
Modified
Description

In Unitrends Backup before 10.4.1, an HTTP request parameter was not properly sanitized, allowing for SQL injection that resulted in an authentication bypass.

Vendors
unitrends
Products
backup
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.