Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-24971

Опубликовано: 04 фев. 2025
Источник: nvd
EPSS Средний

Описание

DumpDrop is a stupid simple file upload application that provides an interface for dragging and dropping files. An OS Command Injection vulnerability was discovered in the DumbDrop application, /upload/init endpoint. This vulnerability could allow an attacker to execute arbitrary code remotely when the Apprise Notification enabled. This issue has been addressed in commit 4ff8469d and all users are advised to patch. There are no known workarounds for this vulnerability.

EPSS

Процентиль: 98%
0.49049
Средний

Дефекты

CWE-78

EPSS

Процентиль: 98%
0.49049
Средний

Дефекты

CWE-78