CVE-2020-27304

CRITICAL

CivetWeb 1.8-1.14 - Path Traversal via File Upload Form Handler

Title source: llm
STIX 2.1

Description

The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_handle_form_request API. Web applications that use the file upload form handler, and use parts of the user-controlled filename in the output path, are susceptible to directory traversal

References (4)

Core 4
Core References
Mailing List, Third Party Advisory x_refsource_misc
https://groups.google.com/g/civetweb/c/yPBxNXdGgJQ
Patch, Third Party Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf

Scores

CVSS v3 9.8
EPSS 0.0100
EPSS Percentile 77.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-22 CWE-23
Status published
Products (2)
civetweb_project/civetweb 1.8 - 1.15
siemens/sinec_infrastructure_network_services < 1.0.1.1
Published Oct 21, 2021
Tracked Since Feb 18, 2026