What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in supsystic.Com Popup by Supsystic allows Relative Path Traversal.This issue affects Popup by Supsystic: from n/a through 1.10.19.
Explanation of Vulnerability in Simple Terms
02Summary
Popup by Supsystic versions up to 1.10.19 contain a path traversal vulnerability that allows unauthenticated attackers to read files from the server. An attacker can craft requests to access files outside the intended directory, potentially exposing sensitive configuration files or other data. No user interaction is required. Update to a version newer than 1.10.19.
What an attacker can do
03Attacker Capabilities
Read arbitrary files from the server, including configuration files and other sensitive data.
Potential impact on your site
04Site Impact
Sensitive files on your server may be exposed to anyone on the internet without needing to log in.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
May 17, 2024
CVE published
April 28, 2026
Record updated