First published: Tue May 02 2023(Updated: )
A vulnerability was found in Dreamer CMS up to 4.1.3. It has been declared as problematic. This vulnerability affects the function updatePwd of the file UserController.java of the component Password Hash Calculation. The manipulation leads to inefficient algorithmic complexity. The attack can be initiated remotely. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-227860.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dreamer Cms Project Dreamer Cms | <=4.1.3 | |
<=4.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2473 is a vulnerability found in Dreamer CMS up to version 4.1.3 that affects the UserController.java file in the component Password Hash Calculation.
CVE-2023-2473 has a severity rating of 7.5 (high).
CVE-2023-2473 affects the updatePwd function in the UserController.java file, leading to inefficient algorithmic complexity.
CVE-2023-2473 is associated with CWE-407.
To fix CVE-2023-2473 in Dreamer CMS, a patch or update should be applied to the affected version 4.1.3.