PT-2025-31523 · Copyparty · Copyparty
Ju0X
·
Published
2025-07-31
·
Updated
2025-07-31
·
CVE-2025-54589
Ju0X
·
Published
2025-07-31
·
Updated
2025-07-31
·
CVE-2025-54589
6.3
Medium
Base vector | Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions:
Copyparty versions 1.18.6 and below
Description:
Copyparty is a portable file server susceptible to a reflected Cross-Site Scripting (XSS) issue. When accessing the recent uploads page at `/?ru`, the application does not properly escape user-supplied input in the filter parameter, which is directly reflected into a `<script>` block. This allows attackers to inject malicious scripts. The issue affects both authenticated and unauthenticated users.
Recommendations:
Update to version 1.18.7 or later.
Fix
XSS