CVE-2025-27145
- EPSS 0.46%
- Veröffentlicht 25.02.2025 02:15:16
- Zuletzt bearbeitet 19.09.2025 19:06:29
copyparty, a portable file server, has a DOM-based cross-site scripting vulnerability in versions prior to 1.16.15. The vulnerability is considered low-risk. By handing someone a maliciously-named file, and then tricking them into dragging the file i...
CVE-2023-38501
- EPSS 9.32%
- Veröffentlicht 25.07.2023 22:15:10
- Zuletzt bearbeitet 04.09.2025 13:04:46
copyparty is file server software. Prior to version 1.8.7, the application contains a reflected cross-site scripting via URL-parameter `?k304=...` and `?setck=...`. The worst-case outcome of this is being able to move or delete existing files on the ...
CVE-2023-37474
- EPSS 44.92%
- Veröffentlicht 14.07.2023 20:15:09
- Zuletzt bearbeitet 04.09.2025 13:04:46
Copyparty is a portable file server. Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in the `.cpr` subfolder. The Path Traversal attack technique allows an attacker access to files, directories, and commands that reside...