Impact
DreamMaker, a web application from Interinfo, contains an arbitrary file upload flaw that allows remote attackers to place and execute a web shell on the server. This vulnerability directly leads to unauthorized code execution, potentially compromising the entire web server and any services running on it.
Affected Systems
The affected product is Interinfo DreamMaker. The exact version information is not listed in the data, but the vendor recommends updating to Java Composer 2.3 or later to resolve the issue.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity. Attackers can exploit the flaw remotely without authentication, as stated in the description. The vulnerability is not yet listed in CISA’s KEV catalog, and no EPSS score is available, but the high CVSS and remote nature suggest a high likelihood of exploitation if not patched.
OpenCVE Enrichment