Vulnerabilities
2 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-7757 | This affects all versions of package droppy. This affects all versions of package droppy. It is possible to traverse directories to fetch configuration files from a droopy server. NVD description · AI analysis pending | 6.5 | 2% | PoC |
| — | |
| CVE-2016-10529 | Droppy versions <3.5.0 does not perform any verification for cross-domain websocket requests. Droppy versions <3.5.0 does not perform any verification for cross-domain websocket requests. An attacker is able to make a specially crafted page that can send requests as the context of the currently logged in user. For example this means the malicious user could add a new admin account under his control and delete others. NVD description · AI analysis pending | 8.8 | <1% |
| — |