The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_handle_form_request API. Web applications that use the file upload form handler, and use parts of the user-controlled filename in the output path, are susceptible to directory traversal
Advisories
Source ID Title
EUVD EUVD EUVD-2020-19817 The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_handle_form_request API. Web applications that use the file upload form handler, and use parts of the user-controlled filename in the output path, are susceptible to directory traversal
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VDOO

Published:

Updated: 2024-08-04T16:11:36.691Z

Reserved: 2020-10-19T00:00:00

Link: CVE-2020-27304

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-10-21T16:15:07.737

Modified: 2024-11-21T05:21:01.317

Link: CVE-2020-27304

cve-icon Redhat

Severity : Important

Publid Date: 2021-10-18T00:00:00Z

Links: CVE-2020-27304 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses