Vulnerability Description
Cross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code via a crafted payload to the WEEKEND-PLANS function. NOTE: this is disputed because WEEKEND-PLANS is accessible only to actors who already have write access to the server, and they can more simply upload HTML files containing JavaScript.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| 9001 | Copyparty | 1.9.1 |
Related Weaknesses (CWE)
References
- https://github.com/9001/copypartyProduct
- https://github.com/9001/copyparty/releases/tag/v1.9.2
- https://github.com/Trinity-SYT-SECURITY/XSS_vuln_issue/blob/main/copyparty.mdExploitThird Party Advisory
FAQ
What is CVE-2023-41471?
CVE-2023-41471 is a vulnerability with a CVSS score of 7.8 (HIGH). Cross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code via a crafted payload to the WEEKEND-PLANS function. NOTE: this is disputed because WEEKE...
How severe is CVE-2023-41471?
CVE-2023-41471 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-41471?
Check the references section above for vendor advisories and patch information. Affected products include: 9001 Copyparty.