Path traversal in Backup by Supsystic - #VU50625

 

Path traversal in Backup by Supsystic - #VU50625

Published: February 11, 2021


Vulnerability identifier: #VU50625
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote user to delete arbitrary files on the server.

The vulnerability exists due to input validation error when processing directory traversal sequences passed via the "filename" parameter. A remote user can send a specially crafted HTTP request and delete arbitrary files on the system.

Note, the vulnerability can be exploited via CSRF attack vector.


Affected software

Backup by Supsystic

Remediation

Install updates from vendor's website.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins