Cross Site Scripting Vulnerability in Copyparty by Trinity SYT Security
CVE-2023-41471
7.8HIGH
What is CVE-2023-41471?
The Copyparty application, particularly version 1.9.1, is susceptible to a Cross Site Scripting (XSS) vulnerability. This flaw allows a local attacker to craft a malicious payload targeting the WEEKEND-PLANS function, which can lead to the execution of arbitrary code. Attackers can exploit this vulnerability to manipulate user sessions and gain unauthorized access to sensitive data.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
