CVE-2026-85541: Interinfo|DreamMaker - Reflected Cross-site Scripting
DreamMaker developed by Interinfo has a Reflected Cross-site Scripting vulnerability. Authenticated remote attackers can execute arbitrary JavaScript codes in user's browser via a malicious website.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Java Composer Serverto a version that resolves this vulnerability.Fixed in 2.3 - Compensating control
Stop using baServer3 (use Java Composer Server 2.3 instead).
Event History
Frequently Asked Questions
What access and interaction are required for exploitation?
An attacker must be authenticated to DreamMaker and must induce a user to visit a malicious website. Exploitation is remote and does not require complex attack conditions.
What can an attacker do after successful exploitation?
The attacker can execute arbitrary JavaScript in the affected user's browser. The stated impact includes limited confidentiality and integrity effects, with no availability impact indicated.