← Vulnerability feed

Vulnerability record · CVE-2023-38501 · published 25 July 2023

CVE-2023-38501: 9001 copyparty cross-site scripting vulnerability

99001 · Copyparty

copyparty is file server software. Prior to version 1.8.7, the application contains a reflected cross-site scripting via URL-parameter `?k304=...` and `?setck=...`. The worst-case outcome of this is being able to move or delete existing files on the server, or upload new files, using the account of the person who clicks the malicious link. It is recommended to change the passwords of one's copyparty accounts, unless one have inspected one's logs and found no trace of attacks. Version 1.8.7 contains a patch for the issue.

6.1 CVSS 3.1 Medium EPSS 9.2% · top 4.8% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
9.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

copyparty is file server software. Prior to version 1.8.7, the application contains a reflected cross-site scripting via URL-parameter `?k304=...` and `?setck=...`. The worst-case outcome of this is being able to move or delete existing files on the server, or upload new files, using the account of the person who clicks the malicious link. It is recommended to change the passwords of one's copyparty accounts, unless one have inspected one's logs and found no trace of attacks. Version 1.8.7 contains a patch for the issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-38501 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2023-414719001 copyparty cross-site scripting vulnerabilityCross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code via a crafted payload to the WEEKEND-P…EPSS 0.26%7.5CVE-2025-547969001 copyparty uncontrolled resource consumption vulnerabilityCopyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows arbitrary RegExes. If this f…EPSS 0.42%7.5CVE-2023-37474Copyparty path traversal in .cpr subfolder exposes files outside web rootCopyparty versions before 1.8.2 contain a path traversal flaw in the .cpr subfolder, allowing access to files, directories and commands outside the w…EPSS 45%analysed6.1CVE-2026-279489001 copyparty cross-site scripting vulnerabilityCopyparty is a portable file server. In versions prior to 1.20.9, an XSS allows for reflected cross-site scripting via URL-parameter `?setck=...`. Ve…EPSS 0.27%6.1CVE-2025-545899001 copyparty cross-site scripting vulnerabilityCopyparty is a portable file server. In versions 1.18.6 and below, when accessing the recent uploads page at `/?ru`, users can filter the results usi…EPSS 2.4%6.1CVE-2025-544239001 copyparty cross-site scripting vulnerabilitycopyparty is a portable file server. In versions up to and including versions 1.18.4, an unauthenticated attacker is able to execute arbitrary JavaSc…EPSS 0.40%6.1CVE-2025-271459001 copyparty cross-site scripting vulnerabilitycopyparty, a portable file server, has a DOM-based cross-site scripting vulnerability in versions prior to 1.16.15. The vulnerability is considered l…EPSS 0.47%5.4CVE-2026-309749001 copyparty cross-site scripting vulnerabilityCopyparty is a portable file server. Prior to v1.20.11., the nohtml config option, intended to prevent execution of JavaScript in user-uploaded HTML …EPSS 0.34%

Source: NIST National Vulnerability Database (record CVE-2023-38501), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.