PT-2024-17380 · Interinfo · Dreammaker

Vtim

·

Published

2024-11-29

·

Updated

2024-12-04

·

CVE-2024-11979

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DreamMaker from Interinfo (affected versions not specified)
Description The issue allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells. This is due to a Path Traversal vulnerability and the lack of restriction on the types of uploaded files.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-11979

Affected Products

Dreammaker