Back to CVE List

CVE-2020-37246

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
6.2 / 10
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Vulnerability Description

Supsystic Backup 2.3.9 contains a local file inclusion vulnerability that allows unauthenticated attackers to read and delete arbitrary files by manipulating the download path parameter. Attackers can modify the download parameter in admin.php requests with directory traversal sequences to access sensitive files like /etc/passwd or delete files via the removeAction parameter.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-98
Source
NVD
Vendor
Supsystic
Product
Backup

External References

Discussion (0)

Add Comment

No comments yet. Be the first!