PT-2023-28817 · Iteachyou · Iteachyou Dreamer Cms

·

CVE-2023-43382

·

Published

2023-09-25

·

Updated

2023-09-26

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions itechyou dreamer CMS version 4.1.3
Description A Directory Traversal issue allows a remote attacker to execute arbitrary code via the themePath in the uploaded template function.
Recommendations For itechyou dreamer CMS version 4.1.3, update the software to a version that fixes this issue, or as a temporary workaround, consider restricting access to the uploaded template function to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-43382

Affected Products

Iteachyou Dreamer Cms