CVE-2020-27304 PUBLISHED

The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_handle_form_request API. Web applications that use the file upload form handler, and use parts of the user-controlled filename in the output path, are susceptible to directory traversal

EPSS 0.99% · 76.8th percentile

Risk Scores

EPSS Score
0.99%
76.8th percentile

Affected Products

VendorProductVersions
Ubuntu:24.04:LTScivetweb0, 1.16+dfsg-1, 1.16+dfsg-1build1
Ubuntu:22.04:LTScivetweb1.15+dfsg-3, 0, 1.13+dfsg-5
Ubuntu:25.10civetweb0, *

Timeline

References

Open in Interactive Console →