← Back to browse · API

CVE-2023-37474

Severity
HIGH
CVSS
7.5
EPSS
0.4492
Risk score
45.72
CISA KEV
No
PoC
No
Published
2023-07-14
Modified
2025-02-13
First seen
2026-08-07
Aliases
EUVD-2023-0055, GHSA-PXFV-7RR3-2QJG, PYSEC-2023-127
Products
9001:copyparty < 1.8.2
Sources
euvd EUVD-2023-0055

Description

Copyparty is a portable file server. Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in the `.cpr` subfolder. The Path Traversal attack technique allows an attacker access to files, directories, and commands that reside outside the web document root directory. This issue has been addressed in commit `043e3c7d` which has been included in release 1.8.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.

References