Interinfo DreamMaker
- <= 2.2
A path traversal vulnerability has been identified in Interinfo's DreamMaker, specifically in versions through 2.2. This vulnerability allows unauthenticated remote attackers to read file names from arbitrary paths by exploiting an absolute path traversal flaw.
Exploitation of this vulnerability could lead to unauthorized access to file names under arbitrary paths, potentially allowing for further attacks or information disclosure.
Users are advised to update to DreamMaker version 2.3 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.