Metrics
Affected Vendors & Products
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 12 Sep 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 12 Sep 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was detected in iteachyou Dreamer CMS up to 4.1.3.2. This issue affects some unknown processing of the file /admin/user/updatePwd. Performing manipulation results in weak password requirements. Remote exploitation of the attack is possible. A high degree of complexity is needed for the attack. The exploitability is assessed as difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | iteachyou Dreamer CMS updatePwd weak password | |
Weaknesses | CWE-521 | |
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-09-12T16:55:07.071Z
Reserved: 2025-09-12T08:09:26.707Z
Link: CVE-2025-10320

Updated: 2025-09-12T16:55:01.698Z

Status : Received
Published: 2025-09-12T16:15:33.190
Modified: 2025-09-12T16:15:33.190
Link: CVE-2025-10320

No data.

No data.