CVE-2026-85540: Interinfo|DreamMaker - SQL Injection
Published Sep 4, 2026
·Updated
DreamMaker developed by Interinfo has a SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.
Affected Software
1 affected component
Interinfo DreamMaker
Event History
Sep 4, 2026
CVE Published
via MITRE·09:34 AM
Data Sourced
via MITRE·09:34 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker needs to be authenticated and able to reach the affected DreamMaker instance remotely. No user interaction is required.
2
What could an attacker do after exploiting the vulnerability?
The attacker can inject arbitrary SQL commands, allowing them to read, modify, or delete database contents. This can affect confidentiality, integrity, and availability of data.