Impact
DreamMaker, a web application developed by Interinfo, contains a reflected cross‑site scripting flaw that allows an authenticated remote attacker to inject and execute arbitrary JavaScript in the victim’s browser when the victim visits a specially crafted malicious site. This client‑side attack can be used to hijack the victim’s session, deface the interface, or perform secondary attacks that run with the victim’s privileges and context.
Affected Systems
The vulnerability affects Interinfo’s DreamMaker application; specific version information is not supplied, but the vendor recommends updating to Java Composer Server 2.3 or discontinuing the use of baServer3 to remediate the issue.
Risk and Exploitability
With a CVSS score of 4.8 the vulnerability is of moderate severity and the EPSS score is unavailable. The attack requires the attacker to be an authenticated user within DreamMaker, yet the execution of malicious JavaScript occurs on the client side after the victim accesses a malicious site. Although not listed in the CISA KEV catalog, the vulnerability could still be exploited in environments where authenticated users are exposed to untrusted content. The risk is therefore moderate, with potential for session hijacking or defacement if the attacker successfully tricks a user into visiting the malicious site.
OpenCVE Enrichment