GHSA-f54q-j679-p9hh · Severity: medium · Ecosystem: pip — copyparty vulnerable to reflected cross-site scripting via k304 parameter
copyparty is file server software. Prior to version 1.8.7, the application contains a reflected cross-site scripting via URL-parameter `?k304=...` and `?setck=...`. The worst-case outcome of this is being able to move or delete existing files on the server, or upload new files, using the account of the person who clicks the malicious link. It is recommended to change the passwords of one's copyparty accounts, unless one have inspected one's logs and found no trace of attacks. Version 1.8.7 contains a patch for the issue.
Conclusion & alert: CVE-2023-38501 is rated High Exploit Risk (75.9/100): CVSS Medium severity, with high exploitation likelihood (EPSS 79.63%, 99th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +1.05% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 51635 | exploit_db | edb | 2023-07-28 | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-19 | 78.58% | 79.63% | +1.05% |
| 2 | 2026-04-04 | 80.15% | 78.58% | -1.57% |
| 3 | 2026-03-19 | — | 80.15% | — |
Full EPSS history (31 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.3 | 3.1 | MEDIUM |
|
2.8 | 3.4 | [email protected] |
| 6.1 | 3.1 | MEDIUM |
|
2.8 | 2.7 | [email protected] |
GHSA-f54q-j679-p9hh · Severity: medium · Ecosystem: pip — copyparty vulnerable to reflected cross-site scripting via k304 parameter
| URL | Tags |
|---|---|
| http://packetstormsecurity.com/files/173821/Copyparty-1.8.6-Cross-Site-Scripting.html | Third Party Advisory VDB Entry |
| https://github.com/9001/copyparty/commit/007d948cb982daa05bc6619cd20ee55b7e834c38 | Patch |
| https://github.com/9001/copyparty/security/advisories/GHSA-f54q-j679-p9hh | Vendor Advisory |