Back

MEDIUM

copyparty Reflected XSS via Filter Parameter

Published Jul 31, 2025

Description

Copyparty is a portable file server. In versions 1.18.6 and below, when accessing the recent uploads page at `/?ru`, users can filter the results using an input field at the top. This field appends a filter parameter to the URL, which reflects its value directly into a `<script>` block without proper escaping, allowing for reflected Cross-Site Scripting (XSS) and can be exploited against both authenticated and unauthenticated users. This is fixed in version 1.18.7.

Affected products

Remediation

No remediation recorded yet.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jul 31, 2025
Updated Jul 31, 2025
Reserved Jul 25, 2025
CISA Vulnrichment
Updated Jul 31, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Jul 31, 2025
Updated Jul 31, 2025
Exploited since n/a
EUVD-2025-23272 GHSA-8MX2-RJH8-Q3JQ