Loading
It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unauthenticated user to inject arbitrary commands into its /api/hosts parameters using backquotes.
Use CWE-287, Kaseya vendor hub and Unitrends Backup product page to widen CVE-2018-6328 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-40386, CVE-2021-43044 and CVE-2021-43042 for nearby disclosures in the same product family.