{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-10-01T07:54:36.137","vulnerabilities":[{"cve":{"id":"CVE-2016-10529","sourceIdentifier":"support@hackerone.com","published":"2018-05-31T20:29:00.940","lastModified":"2026-06-17T00:39:53.047","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Droppy versions <3.5.0 does not perform any verification for cross-domain websocket requests. An attacker is able to make a specially crafted page that can send requests as the context of the currently logged in user. For example this means the malicious user could add a new admin account under his control and delete others."},{"lang":"es","value":"Droppy en versiones anteriores a la 3.5.0 no realiza ningún tipo de verificación para peticiones websocket Cross-Domain. Un atacante puede hacer una página especialmente manipulada que puede enviar peticiones como el contexto del usuario que tiene la sesión iniciada actualmente. Por ejemplo, esto significa que el usuario malicioso podría añadir una nueva cuenta de administrador bajo su control, además de eliminar otras."}],"affected":[{"source":"support@hackerone.com","affectedData":[{"vendor":"HackerOne","product":"droppy node module","versions":[{"version":"<3.5.0","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-352"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-352"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:droppy_project:droppy:*:*:*:*:*:node.js:*:*","versionEndExcluding":"3.5.0","matchCriteriaId":"1629CFF8-A569-48DE-B499-8064F26B4A6D"}]}]}],"references":[{"url":"https://nodesecurity.io/advisories/91","source":"support@hackerone.com","tags":["Third Party Advisory"]},{"url":"https://nodesecurity.io/advisories/91","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}}]}