CVE-2023-38501 is a reflected cross-site scripting (XSS) vulnerability affecting copyparty file server software prior to version 1.8.7. This flaw, found in the ?k304= and ?setck= URL parameters, allows an attacker to potentially move, delete, or upload files using the compromised account of a user who clicks a malicious link. With a CVSS score of 6.1 (Medium) and an EPSS score indicating high exploitability, the vulnerability has readily available exploit code via Nuclei templates and ExploitDB, though it is not currently listed on the KEV catalog or Hot List. Despite the availability of exploits, there is currently no recorded community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.8.7CPE matchmatch criteria | cpe:2.3:a:9001:copyparty:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.