First published: Wed Nov 29 2023(Updated: )
In Dreamer CMS before 4.0.1, the backend attachment management office has an Arbitrary File Download vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dreamer Cms Project Dreamer Cms | <4.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-46887 is an Arbitrary File Download vulnerability in Dreamer CMS before 4.0.1.
CVE-2023-46887 has a severity value of 7.5, indicating a high severity.
CVE-2023-46887 allows arbitrary file downloads in the backend attachment management office of Dreamer CMS before 4.0.1.
The affected software version of CVE-2023-46887 is Dreamer CMS before 4.0.1.
To fix CVE-2023-46887, update to Dreamer CMS version 4.0.1 or later.