Cross Site Scripting Vulnerability in Copyparty by Trinity SYT Security
CVE-2023-41471

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
29 August 2025

What is CVE-2023-41471?

The Copyparty application, particularly version 1.9.1, is susceptible to a Cross Site Scripting (XSS) vulnerability. This flaw allows a local attacker to craft a malicious payload targeting the WEEKEND-PLANS function, which can lead to the execution of arbitrary code. Attackers can exploit this vulnerability to manipulate user sessions and gain unauthorized access to sensitive data.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.