PT-2026-5378 · Interinfo · Interinfo Dreammaker

Kuang Ming Chang

·

Publicado

2026-01-30

·

Atualizado

2026-01-30

·

CVE-2026-24729

CVSS v4.0

10

Crítica

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Interinfo DreamMaker versions prior to 2025/10/22
Description A flaw exists in the file upload functionality of Interinfo DreamMaker that permits unrestricted file uploads of dangerous file types. This can allow remote attackers to execute arbitrary system commands by uploading a malicious class file.
Recommendations Update Interinfo DreamMaker to version 2025/10/22 or later.

Correção

RCE

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-24729

Produtos afetados

Interinfo Dreammaker