---
id: CVE-2020-37246
title: >-
  Supsystic Backup 2.3.9 contains a local file inclusion vulnerability that
  allows unauthenticated attackers to read and delete arbitrary files by
  manipulating the download path parameter
summary: >-
  Supsystic Backup 2.3.9 contains a local file inclusion vulnerability that
  allows unauthenticated attackers to read and delete arbitrary files by
  manipulating the download path parameter. Attackers can modify the download
  parameter in adm…
severity: medium
cvss: 6.2
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-98
published: '2026-05-16'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T10:10:00.263'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-37246'
references:
  - url: 'https://downloads.wordpress.org/plugin/backup-by-supsystic.zip'
    label: disclosure@vulncheck.com
  - url: 'https://supsystic.com/'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/49545'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/wordpress-plugin-supsystic-backup-local-file-inclusion
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00673
epssPercentile: 0.50167
ingestedAt: '2026-09-29T10:31:36.290Z'
---

## Overview

Supsystic Backup 2.3.9 contains a local file inclusion vulnerability that allows unauthenticated attackers to read and delete arbitrary files by manipulating the download path parameter. Attackers can modify the download parameter in admin.php requests with directory traversal sequences to access sensitive files like /etc/passwd or delete files via the removeAction parameter.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
