First published: Sun Dec 24 2023(Updated: )
A vulnerability was found in Dreamer CMS 4.1.3. It has been declared as problematic. This vulnerability affects unknown code of the file /upload/uploadFile. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-248938 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
iteachyou Dreamer CMS | =4.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-7091 has been declared as a problematic vulnerability affecting Dreamer CMS 4.1.3.
To fix CVE-2023-7091, users should upgrade to a patched version of Dreamer CMS that addresses the unrestricted upload flaw.
CVE-2023-7091 is an unrestricted file upload vulnerability that can be exploited remotely.
CVE-2023-7091 specifically affects Dreamer CMS version 4.1.3.
Yes, the exploit for CVE-2023-7091 can be initiated remotely, indicating it may not require authentication.