CVE-2025-27145

CVSS 3.1 Score 3.6 of 10 (low)

Details

Published Feb 25, 2025
CWE ID 83
CWE ID 79

Summary

CVE-2025-27145 is a low-risk DOM-based cross-site scripting (XSS) vulnerability affecting copyparty, a portable file server, prior to version 1.16.15. An attacker can exploit this flaw by tricking a user into dragging and dropping a maliciously-named empty file into copyparty's Web-UI. This action would execute arbitrary JavaScript with the same privileges as the user, potentially granting unintended read-access to their files. The uploaded file doesn't need to be opened for the script to run; instead, it triggers during the act of uploading. Unlike regular HTML file uploads, this vulnerability executes JavaScript during the upload process, posing a distinct threat. Copyparty version 1.16.15 includes a fix for this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share