First published: Thu Feb 29 2024(Updated: )
An access control issue in Dreamer CMS v4.0.1 allows attackers to download backup files and leak sensitive information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
iteachyou Dreamer CMS | ||
Dreamer CMS | =4.0.1 | |
Dreamer CMS | =4.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25811 is rated as a high-severity vulnerability due to its potential to expose sensitive information through unauthorized access to backup files.
To fix CVE-2024-25811, it is essential to implement strict access controls and ensure that unauthorized users cannot access backup file directories.
CVE-2024-25811 affects Dreamer CMS version 4.0.1, which is a content management system.
Attackers exploiting CVE-2024-25811 can download backup files, potentially leaking sensitive information stored within.
Yes, CVE-2024-25811 specifically impacts Dreamer CMS version 4.0.1 and may not affect other versions.