In Dreamer CMS before 4.0.1, the backend attachment management office has an Arbitrary File Download vulnerability.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-51053 In Dreamer CMS before 4.0.1, the backend attachment management office has an Arbitrary File Download vulnerability.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 04 Apr 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Iteachyou
Iteachyou dreamer Cms
CPEs cpe:2.3:a:dreamer_cms_project:dreamer_cms:*:*:*:*:*:*:*:* cpe:2.3:a:iteachyou:dreamer_cms:*:*:*:*:*:*:*:*
Vendors & Products Dreamer Cms Project
Dreamer Cms Project dreamer Cms
Iteachyou
Iteachyou dreamer Cms

Tue, 26 Nov 2024 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-11-26T20:31:21.220Z

Reserved: 2023-10-30T00:00:00

Link: CVE-2023-46887

cve-icon Vulnrichment

Updated: 2024-08-02T20:53:21.948Z

cve-icon NVD

Status : Modified

Published: 2023-11-29T05:15:07.980

Modified: 2025-04-04T15:15:06.847

Link: CVE-2023-46887

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.