Description
The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_handle_form_request API. Web applications that use the file upload form handler, and use parts of the user-controlled filename in the output path, are susceptible to directory traversal
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-19817 | The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_handle_form_request API. Web applications that use the file upload form handler, and use parts of the user-controlled filename in the output path, are susceptible to directory traversal |
References
History
No history.
Status: PUBLISHED
Assigner: VDOO
Published:
Updated: 2024-08-04T16:11:36.691Z
Reserved: 2020-10-19T00:00:00.000Z
Link: CVE-2020-27304
No data.
Status : Modified
Published: 2021-10-21T16:15:07.737
Modified: 2024-11-21T05:21:01.317
Link: CVE-2020-27304
OpenCVE Enrichment
No data.
EUVD