Back to search
CVE-2025-47929
Published: May 15, 2025
Modified: May 28, 2025
PUBLISHED
Description
DumbDrop, a file upload application that provides an interface for dragging and dropping files, has a DOM cross-site scripting vulnerability in the upload functionality prior to commit db27b25372eb9071e63583d8faed2111a2b79f1b. A user could be tricked into uploading a file with a malicious payload. Commit db27b25372eb9071e63583d8faed2111a2b79f1b fixes the vulnerability.
| Vendor | Product | Versions |
|---|---|---|
DumbWareio | DumbDrop | affected < db27b25372eb9071e63583d8faed2111a2b79f1b |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now