First published: Sun Sep 03 2023(Updated: )
A vulnerability was found in Dreamer CMS up to 4.1.3. It has been classified as problematic. Affected is an unknown function of the file /upload/ueditorConfig?action=config. The manipulation leads to files or directories accessible. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-238632. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dreamer Cms Project Dreamer Cms | <=4.1.3 | |
<=4.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-4743 is medium with a rating of 4.8.
The affected software of CVE-2023-4743 is Dreamer CMS up to version 4.1.3.
The vulnerability in CVE-2023-4743 can be exploited remotely by manipulating an unknown function in the /upload/ueditorConfig?action=config file, allowing unauthorized access to files or directories.
There is no information available about a fix for CVE-2023-4743 at the moment. It is recommended to follow the provided references for updates.
The Common Weakness Enumeration (CWE) of CVE-2023-4743 is CWE-552.