Vulnerability record · CVE-2020-27304 · published 21 October 2021
CVE-2020-27304: Civetweb project civetweb relative path traversal vulnerability
CCivetweb Project · Civetweb
The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_handle_form_request API. Web applications that use the file upload form handler, and use parts of the user-controlled filename in the output path, are susceptible to directory traversal
Description
The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_handle_form_request API. Web applications that use the file upload form handler, and use parts of the user-controlled filename in the output path, are susceptible to directory traversal
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdf | |
| https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf | PatchThird Party Advisory |
| https://groups.google.com/g/civetweb/c/yPBxNXdGgJQ | Mailing ListThird Party Advisory |
| https://jfrog.com/blog/cve-2020-27304-rce-via-directory-traversal-in-civetweb-http-server/ | ExploitThird Party Advisory |
| https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdf | |
| https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf | PatchThird Party Advisory |
| https://groups.google.com/g/civetweb/c/yPBxNXdGgJQ | Mailing ListThird Party Advisory |
| https://jfrog.com/blog/cve-2020-27304-rce-via-directory-traversal-in-civetweb-http-server/ | ExploitThird Party Advisory |
Track CVE-2020-27304 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-27304), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.