Description
DreamMaker developed by Interinfo has a Reflected Cross-site Scripting vulnerability. Authenticated remote attackers can execute arbitrary JavaScript codes in user's browser via a malicious website.
Published: 2026-09-04
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

DreamMaker, a web application developed by Interinfo, contains a reflected cross‑site scripting flaw that allows an authenticated remote attacker to inject and execute arbitrary JavaScript in the victim’s browser when the victim visits a specially crafted malicious site. This client‑side attack can be used to hijack the victim’s session, deface the interface, or perform secondary attacks that run with the victim’s privileges and context.

Affected Systems

The vulnerability affects Interinfo’s DreamMaker application; specific version information is not supplied, but the vendor recommends updating to Java Composer Server 2.3 or discontinuing the use of baServer3 to remediate the issue.

Risk and Exploitability

With a CVSS score of 4.8 the vulnerability is of moderate severity and the EPSS score is unavailable. The attack requires the attacker to be an authenticated user within DreamMaker, yet the execution of malicious JavaScript occurs on the client side after the victim accesses a malicious site. Although not listed in the CISA KEV catalog, the vulnerability could still be exploited in environments where authenticated users are exposed to untrusted content. The risk is therefore moderate, with potential for session hijacking or defacement if the attacker successfully tricks a user into visiting the malicious site.

Generated by OpenCVE AI on September 4, 2026 at 10:21 UTC.

Remediation

Vendor Solution

Update to version Java Composer Server 2.3 or stop using baServer3.


OpenCVE Recommended Actions

  • Apply the vendor’s official patch by upgrading DreamMaker to Java Composer Server 2.3 or later.
  • If upgrading is not immediately possible, discontinue the use of baServer3 as instructed by the vendor.
  • Implement request filtering or a web application firewall rule to block the injection of malicious JavaScript characters in reflected responses.

Generated by OpenCVE AI on September 4, 2026 at 10:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Interinfo
Interinfo dreammaker
Vendors & Products Interinfo
Interinfo dreammaker

Fri, 04 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Description DreamMaker developed by Interinfo has a Reflected Cross-site Scripting vulnerability. Authenticated remote attackers can execute arbitrary JavaScript codes in user's browser via a malicious website.
Title Interinfo|DreamMaker - Reflected Cross-site Scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Interinfo Dreammaker
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-09-04T09:35:26.412Z

Reserved: 2026-09-04T09:08:33.437Z

Link: CVE-2026-85541

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-04T10:17:14.153

Modified: 2026-09-04T10:17:14.153

Link: CVE-2026-85541

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T10:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')