PT-2018-4709 · Droppy · Droppy
Published
2018-05-31
·
Updated
2019-10-09
·
CVE-2016-10529
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Droppy versions prior to 3.5.0
Description
The issue concerns a lack of verification for cross-domain websocket requests. This allows an attacker to create a specially crafted page that can send requests on behalf of the currently logged-in user. As a result, the attacker can perform actions such as adding a new admin account or deleting existing ones.
Recommendations
Update to version 3.5.0 or later.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Droppy