← back
CVE-2020-37246mediumCWE-98

WordPress Plugin Supsystic Backup 2.3.9 Local File Inclusion

33Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 6.9epss 0.7%
exploitation probability
0.7%top 51% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Supsystic Backup 2.3.9 contains a local file inclusion vulnerability that allows unauthenticated attackers to read and delete arbitrary files by manipulating the download path parameter. Attackers can modify the download parameter in admin.php requests with directory traversal sequences to access sensitive files like /etc/passwd or delete files via the removeAction parameter.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
Supsystic · Backup
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.