S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-38501 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Copyparty affects v. prior to 1.8.6.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-38501
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

copyparty is file server software. Prior to version 1.8.7, the application contains a reflected cross-site scripting via URL-parameter `?k304=...` and `?setck=...`. The worst-case outcome of this is being able to move or delete existing files on the server, or upload new files, using the account of the person who clicks the malicious link. It is recommended to change the passwords of one's copyparty accounts, unless one have inspected one's logs and found no trace of attacks. Version 1.8.7 contains a patch for the issue.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
copypartyby 9001
< 1.8.7
copypartyby copyparty_project
AFFECTED< 1.8.7SAFE ✓≥ 1.8.7
Updated Aug 22, 2026View on NVD →
Detail

Copyparty is a file server software that allows users to host and share files with others. It is a popular application used in various industries where sharing large files is a necessity. The software is designed for both personal and professional use, and its features include secure encrypted transfers, user management, and powerful search capabilities. Copyparty simplifies file-sharing by eliminating the need for third-party services, providing a fast and reliable way to share files.

CVE-2023-38501 is a vulnerability that was detected in Copyparty prior to version 1.8.7. This vulnerability is a reflected cross-site scripting via URL-parameter `?k304=...` and `?setck=...`. This type of vulnerability can be exploited by attackers to execute malicious code on the user's browser. An attacker can create a link that includes the malicious code and send it to a user. If the user clicks on the link, the code can allow the attacker to take control over the user's account and potentially access sensitive information.

When exploited, this vulnerability can lead to unfortunate outcomes. An attacker can use the user's account to upload malicious files that can harm the user and others who download or access the files. Additionally, the attacker can delete important files, compromising the integrity of the user's data. In the worst-case scenario, an attacker can take control over the entire server, causing significant damage to all the users of the software.

Thanks to the pro features of the s4e.io platform, users are able to easily and quickly learn about vulnerabilities in their digital assets. The platform provides vulnerability scanning, penetration testing, and security assessments. It is an essential tool for those who want to ensure that their digital assets are secure and protected. As more and more businesses move online, having a reliable and effective security platform is essential. With s4e.io, users can be confident that their digital assets are in good hands.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users of Copyparty can take some precautions. Here are some examples:

  • Update to the latest version of Copyparty (version 1.8.7) that contains a patch for the issue.
  • Change passwords regularly and ensure that they are strong and unique.
  • Be cautious when clicking on links, especially suspicious ones.
  • Check logs regularly for any suspicious activity.
  • Implement additional security measures such as two-factor authentication and network firewalls.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.