Impact
DreamMaker, a product from Interinfo, contains a classic SQL injection flaw. Unsanitized input is passed to the database layer, enabling an attacker with valid credentials to execute arbitrary SQL statements. This could allow the attacker to read sensitive data, modify important records, or delete content from the database, thereby compromising confidentiality, integrity, and availability of stored information.
Affected Systems
Interinfo DreamMaker. The public data does not specify affected version numbers, so all installations may be vulnerable until a fix is applied.
Risk and Exploitability
The CVSS score of 8.7 marks it as high severity, although an EPSS score is not available in the report. It is not yet listed in the CISA KEV catalog. The attack requires an authenticated remote user, suggesting the attacker must first log in to the application, then supply malicious input through a form or other interface that transmits the data to the database.
OpenCVE Enrichment