Supsystic Backup 2.3.9 contains a local file inclusion vulnerability that allows unauthenticated attackers to read and delete arbitrary files by manipulating the download path parameter. Attackers can modify the download parameter in admin.php requests with directory traversal sequences to access sensitive files like /etc/passwd or delete files via the removeAction parameter.
Metrics
Affected Vendors & Products
References
History
Mon, 18 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 17 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Supsystic
Supsystic backup Wordpress Wordpress wordpress |
|
| Vendors & Products |
Supsystic
Supsystic backup Wordpress Wordpress wordpress |
Sat, 16 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Supsystic Backup 2.3.9 contains a local file inclusion vulnerability that allows unauthenticated attackers to read and delete arbitrary files by manipulating the download path parameter. Attackers can modify the download parameter in admin.php requests with directory traversal sequences to access sensitive files like /etc/passwd or delete files via the removeAction parameter. | |
| Title | WordPress Plugin Supsystic Backup 2.3.9 Local File Inclusion | |
| Weaknesses | CWE-98 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-05-16T15:26:01.314Z
Updated: 2026-05-18T17:53:28.342Z
Reserved: 2026-05-16T14:20:25.326Z
Link: CVE-2020-37246
Updated: 2026-05-18T17:37:02.794Z
Status : Deferred
Published: 2026-05-16T16:16:20.993
Modified: 2026-05-18T17:32:04.823
Link: CVE-2020-37246
No data.
ReportizFlow