Droppy
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-10529 | Hig | 0.57 | 8.8 | 0.00 | May 31, 2018 | Droppy versions <3.5.0 does not perform any verification for cross-domain websocket requests. An attacker is able to make a specially crafted page that can send requests as the context of the currently logged in user. For example this means the malicious user could add a new… | ||
| CVE-2020-7757 | Med | 0.42 | 6.5 | 0.02 | Nov 2, 2020 | This affects all versions of package droppy. It is possible to traverse directories to fetch configuration files from a droopy server. |
- risk 0.57cvss 8.8epss 0.00
Droppy versions <3.5.0 does not perform any verification for cross-domain websocket requests. An attacker is able to make a specially crafted page that can send requests as the context of the currently logged in user. For example this means the malicious user could add a new…
- risk 0.42cvss 6.5epss 0.02
This affects all versions of package droppy. It is possible to traverse directories to fetch configuration files from a droopy server.