PT-2018-4709 · Droppy · Droppy

Published

2018-05-31

·

Updated

2019-10-09

·

CVE-2016-10529

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Droppy versions prior to 3.5.0
Description The issue concerns a lack of verification for cross-domain websocket requests. This allows an attacker to create a specially crafted page that can send requests on behalf of the currently logged-in user. As a result, the attacker can perform actions such as adding a new admin account or deleting existing ones.
Recommendations Update to version 3.5.0 or later.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-10529
GHSA-RHVC-X32H-5526

Affected Products

Droppy