cbcvebase.
CVE-2020-27304
published 2021-10-21

CVE-2020-27304: The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload…

PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.14%
86.4th percentile
The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_handle_form_request API. Web applications that use the file upload form handler, and use parts of the user-controlled filename in the output path, are susceptible to directory traversal

Affected

12 ranges
VendorProductVersion rangeFixed in
civetweb_projectcivetweb>= 0 < 1.15+dfsg-11.15+dfsg-1
civetweb_projectcivetweb>= 0 < 1.15+dfsg-11.15+dfsg-1
civetweb_projectcivetweb>= 0 < 1.15+dfsg-11.15+dfsg-1
civetweb_projectcivetweb>= 1.8 < unspecifiedunspecified
civetweb_projectcivetweb>= 1.8 < 1.151.15
debiancivetweb< civetweb 1.15+dfsg-1 (bookworm)civetweb 1.15+dfsg-1 (bookworm)
msrcazl3_ceph_16.2.10-3_on_azure_linux_3.0
msrcazl3_ceph_18.2.1-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_ceph_16.2.10-7_on_cbl_mariner_2.0
siemenssinec_infrastructure_network_services< 1.0.1.11.0.1.1

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_msrc9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.