Vulnerabilities/

No CSRF Validation in droppy

Severity:
High

Description

Affected versions of droppy are vulnerable to cross-site socket forgery. The package does not perform verification for cross-domain websocket requests, and as a result, an attacker can create a web page that opens up a websocket connection on behalf of the user visiting the page.

Recommendation

Update the droppy package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
droppy
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing