This is a summary of the AI-generated 10-question deep analysis. The full version (longer answers, follow-up Q&A, related CVEs) requires login.
Read the full analysis โ
Q1What is this vulnerability? (Essence + Consequences)
๐จ **Essence**: A **Path Traversal** flaw in Copyparty. ๐ Attackers access files **outside** the web root via the `.cpr` subfolder.โฆ
๐ก๏ธ **CWE-22**: Improper Limitation of a Pathname to a Restricted Directory. ๐ **Flaw**: The application fails to sanitize user input for the `.cpr` endpoint, allowing `../` sequences to escape the intended directory.
Q3Who is affected? (Versions/Components)
๐ฅ **Affected**: Users running **Copyparty** (portable file server by ed). ๐ **Versions**: All versions **prior to 1.8.2**. ๐ท๏ธ **Vendor**: 9001.
Q4What can hackers do? (Privileges/Data)
๐ต๏ธ **Privileges**: Attacker gains **Read-Only** access to arbitrary files. ๐ **Data**: Can view config files, logs, or other sensitive data residing outside the document root.โฆ
๐ฅ **Public Exp?**: **YES**. PoCs available on GitHub (e.g., `ilqarli27/CVE-2023-37474`) and Nuclei templates. ๐ **Wild Exploitation**: High risk due to easy-to-use automated scanning tools.
Q7How to self-check? (Features/Scanning)
๐ **Self-Check**: Scan for Copyparty instances. ๐งช **Test**: Send requests with `../` payloads to the `.cpr` subfolder. ๐ก **Tools**: Use Nuclei templates (`http/cves/2023/CVE-2023-37474.yaml`) for automated detection.
Q8Is it fixed officially? (Patch/Mitigation)
โ **Fixed**: **YES**. Patched in **Version 1.8.2**. ๐ **Commit**: `043e3c7d`. ๐ข **Action**: Upgrade immediately to the latest stable version.
Q9What if no patch? (Workaround)
๐ง **No Patch?**: **No known workarounds** officially listed. ๐ **Mitigation**: Restrict network access to the Copyparty instance.โฆ
โก **Urgency**: **HIGH**. ๐ **Published**: July 2023. ๐จ **Priority**: Critical for exposed servers. Public exploits exist. Upgrade ASAP to prevent data theft.