copyparty Reflected XSS via Filter Parameter

CVE Details

Basic Information

Title copyparty Reflected XSS via Filter Parameter
Type cve
Published 2025-07-31T13:48:41.615Z
Modified 2025-07-31T14:12:45.463Z

Product Information

Vendor 9001
Product copyparty
Version < 1.18.7

CVSS Information

Base Score 6.3 (MEDIUM)
Attack Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

AI Analysis

AI Description A reflected XSS vulnerability in Copyparty’s recent uploads page allows attackers to execute scripts via the filter input, affecting both authenticated and unauthenticated users.
AI Severity Medium
AI Vendor 9001
AI Product copyparty
AI Version 1.18.6 and below

Affected Products

  • 9001 copyparty < 1.18.7

Additional Information

CWE List CWE-79, CWE-80
Source GitHub_M

Description

Copyparty is a portable file server. In versions 1.18.6 and below, when accessing the recent uploads page at `/?ru`, users can filter the results using an input field at the top. This field appends a filter parameter to the URL, which reflects its value directly into a `