The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_handle_form_request API. Web applications that use the file upload form handler, and use parts of the user-controlled filename in the output path, are susceptible to directory traversal
Conclusion & alert: CVE-2020-27304 is rated High Exploit Risk (80.7/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 1.00%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-11-21 | 1.16% | 1.00% | -0.16% |
| 2 | 2025-11-18 | 1.00% | 1.16% | +0.16% |
| 3 | 2025-06-18 | — | 1.00% | — |
Full EPSS history (19 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2020-27304 unimportant priority: Debian including 1 source packages (civetweb), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 4, open 1. | https://security-tracker.debian.org/tracker/CVE-2020-27304 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2020-27304 |
ubuntu
|
medium | CVE-2020-27304 medium priority: Ubuntu including 1 source packages (civetweb), 13 status rows across 13 suites (hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): ignored 9, needs-triage 4. | https://ubuntu.com/security/CVE-2020-27304 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| civetweb_project | civetweb | >= 1.8, < 1.15 | cpe:2.3:a:civetweb_project:civetweb:*:*:*:*:*:*:*:* |
| siemens | sinec_infrastructure_network_services | < 1.0.1.1 | cpe:2.3:a:siemens:sinec_infrastructure_network_services:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdf | |
| https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf | Patch Third Party Advisory |
| https://groups.google.com/g/civetweb/c/yPBxNXdGgJQ | Mailing List Third Party Advisory |
| https://jfrog.com/blog/cve-2020-27304-rce-via-directory-traversal-in-civetweb-http-server/ | Exploit Third Party Advisory |