PT-2026-5378 · Interinfo · Interinfo Dreammaker

Kuang Ming Chang

·

Published

2026-01-30

·

Updated

2026-01-30

·

CVE-2026-24729

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Interinfo DreamMaker versions prior to 2025/10/22
Description A flaw exists in the file upload functionality of Interinfo DreamMaker that permits unrestricted file uploads of dangerous file types. This can allow remote attackers to execute arbitrary system commands by uploading a malicious class file.
Recommendations Update Interinfo DreamMaker to version 2025/10/22 or later.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2026-24729

Affected Products

Interinfo Dreammaker