CVE-2020-37246
MEDIUMWordPress Plugin Supsystic Backup 2.3.9 Local File Inclusion
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2020-37246. PoCs published by Erik David Martin.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in WordPress Plugin Supsystic Backup 2.3.9, allowing attackers to read and delete arbitrary files on the server via path manipulation in backup download and deletion requests.
Description
Supsystic Backup 2.3.9 contains a local file inclusion vulnerability that allows unauthenticated attackers to read and delete arbitrary files by manipulating the download path parameter. Attackers can modify the download parameter in admin.php requests with directory traversal sequences to access sensitive files like /etc/passwd or delete files via the removeAction parameter.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in WordPress Plugin Supsystic Backup 2.3.9, allowing attackers to read and delete arbitrary files on the server via path manipulation in backup download and deletion requests.
References (4)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N