An attacker can overwrite any existing files via backup functionality because the system does not properly validate which files are contained in the backup archive.

CWE: CWE-20:Improper Input Validation