Goal Reached Thanks to every supporter โ€” we hit 100%!

Goal: 1000 CNY ยท Raised: 1359 CNY

100%

CVE-2023-37474 โ€” AI Deep Analysis Summary

Q1What is this vulnerability? (Essence + Consequences)

๐Ÿšจ **Essence**: A **Path Traversal** flaw in Copyparty. ๐Ÿ“‚ Attackers access files **outside** the web root via the `.cpr` subfolder.โ€ฆ

Q2Root Cause? (CWE/Flaw)

๐Ÿ›ก๏ธ **CWE-22**: Improper Limitation of a Pathname to a Restricted Directory. ๐Ÿ› **Flaw**: The application fails to sanitize user input for the `.cpr` endpoint, allowing `../` sequences to escape the intended directory.

Q3Who is affected? (Versions/Components)

๐Ÿ‘ฅ **Affected**: Users running **Copyparty** (portable file server by ed). ๐Ÿ“‰ **Versions**: All versions **prior to 1.8.2**. ๐Ÿท๏ธ **Vendor**: 9001.

Q4What can hackers do? (Privileges/Data)

๐Ÿ•ต๏ธ **Privileges**: Attacker gains **Read-Only** access to arbitrary files. ๐Ÿ“„ **Data**: Can view config files, logs, or other sensitive data residing outside the document root.โ€ฆ

Q5Is exploitation threshold high? (Auth/Config)

๐Ÿ”“ **Threshold**: Likely **Low**. Path traversal often requires no authentication if the `.cpr` endpoint is publicly accessible.โ€ฆ

Q6Is there a public Exp? (PoC/Wild Exploitation)

๐Ÿ”ฅ **Public Exp?**: **YES**. PoCs available on GitHub (e.g., `ilqarli27/CVE-2023-37474`) and Nuclei templates. ๐Ÿš€ **Wild Exploitation**: High risk due to easy-to-use automated scanning tools.

Q7How to self-check? (Features/Scanning)

๐Ÿ” **Self-Check**: Scan for Copyparty instances. ๐Ÿงช **Test**: Send requests with `../` payloads to the `.cpr` subfolder. ๐Ÿ“ก **Tools**: Use Nuclei templates (`http/cves/2023/CVE-2023-37474.yaml`) for automated detection.

Q8Is it fixed officially? (Patch/Mitigation)

โœ… **Fixed**: **YES**. Patched in **Version 1.8.2**. ๐Ÿ”— **Commit**: `043e3c7d`. ๐Ÿ“ข **Action**: Upgrade immediately to the latest stable version.

Q9What if no patch? (Workaround)

๐Ÿšง **No Patch?**: **No known workarounds** officially listed. ๐Ÿ›‘ **Mitigation**: Restrict network access to the Copyparty instance.โ€ฆ

Q10Is it urgent? (Priority Suggestion)

โšก **Urgency**: **HIGH**. ๐Ÿ“… **Published**: July 2023. ๐Ÿšจ **Priority**: Critical for exposed servers. Public exploits exist. Upgrade ASAP to prevent data theft.