DreamMaker from Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.

Project Subscriptions

Vendors Products
Interinfo Subscribe
Dreammaker Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2024-34238 DreamMaker from Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.
Fixes

Solution

Update to version 2024/09/26 or later.


Workaround

No workaround given by the vendor.

History

Fri, 29 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Interinfo
Interinfo dreammaker
CPEs cpe:2.3:a:interinfo:dreammaker:*:*:*:*:*:*:*:*
Vendors & Products Interinfo
Interinfo dreammaker
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 29 Nov 2024 02:30:00 +0000

Type Values Removed Values Added
Description DreamMaker from Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.
Title Interinfo DreamMaker - Arbitrary File Reading through Path Traversal
Weaknesses CWE-36
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-12-03T06:06:38.751Z

Reserved: 2024-11-29T01:52:15.326Z

Link: CVE-2024-11978

cve-icon Vulnrichment

Updated: 2024-11-29T16:37:12.340Z

cve-icon NVD

Status : Received

Published: 2024-11-29T03:15:14.700

Modified: 2024-11-29T03:15:14.700

Link: CVE-2024-11978

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses