HIGH🇵🇱 Wersja polska

CVE-2023-37474

CVSS 7.5v3.1pub. 2023-07-14upd. 2025-09-04

Copyparty is a portable file server. Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in the `.cpr` subfolder. The Path Traversal attack technique allows an attacker access to files, directories, and commands that reside outside the web document root directory. This issue has been addressed in commit `043e3c7d` which has been included in release 1.8.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • 9001 Copyparty

    APP
    9001
    < 1.8.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2023-41471HIGH7.8same product

Cross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code...

CVE-2025-54796HIGH7.5same product

Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" p...

CVE-2026-30974MEDIUM4.6same product

Copyparty to przenośny serwer plików. Przed wersją 1.20.11 opcja konfiguracyjna nohtml, mająca zapobiegać wyko...

CVE-2026-27948MEDIUM5.4same product

Copyparty to przenośny serwer plików. W wersjach przed 1.20.9 podatność XSS umożliwia reflected cross-site scr...

CVE-2025-58753MEDIUM5.3same product

Copyparty is a portable file server. In versions prior to 1.19.8, there was a missing permission-check in the ...