Interinfo DreamMaker Path Traversal Vulnerability Allowing Arbitrary File Name Disclosure

Vulnerability

A path traversal vulnerability has been identified in Interinfo's DreamMaker, specifically in versions through 2.2. This vulnerability allows unauthenticated remote attackers to read file names from arbitrary paths by exploiting an absolute path traversal flaw.

Impact

Exploitation of this vulnerability could lead to unauthorized access to file names under arbitrary paths, potentially allowing for further attacks or information disclosure.

Remediation

Users are advised to update to DreamMaker version 2.3 or later.

Added: May 29, 2026, 2:36 PM
Updated: May 29, 2026, 2:36 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.2
exploitability
7.4
remediation
0.0
relevance
9.7
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.