Show filters
31 Total Results
Displaying 1-10 of 31
Sort by:
Attacker Value
Unknown
CVE-2024-3118
Disclosure Date: March 31, 2024 (last updated April 11, 2024)
A vulnerability, which was classified as critical, has been found in Dreamer CMS up to 4.1.3. This issue affects some unknown processing of the component Attachment Handler. The manipulation leads to permission issues. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258779. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2024-2354
Disclosure Date: March 10, 2024 (last updated April 01, 2024)
A vulnerability, which was classified as problematic, was found in Dreamer CMS 4.1.3. Affected is an unknown function of the file /admin/menu/toEdit. The manipulation of the argument id leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-256314 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2023-46887
Disclosure Date: November 29, 2023 (last updated December 06, 2023)
In Dreamer CMS before 4.0.1, the backend attachment management office has an Arbitrary File Download vulnerability.
0
Attacker Value
Unknown
CVE-2023-46886
Disclosure Date: November 29, 2023 (last updated December 06, 2023)
Dreamer CMS before version 4.0.1 is vulnerable to Directory Traversal. Background template management allows arbitrary modification of the template file, allowing system sensitive files to be read.
0
Attacker Value
Unknown
CVE-2023-48017
Disclosure Date: November 18, 2023 (last updated November 25, 2023)
Dreamer_cms 4.1.3 is vulnerable to Cross Site Request Forgery (CSRF) via Add permissions to CSRF in Permission Management.
0
Attacker Value
Unknown
CVE-2023-48063
Disclosure Date: November 13, 2023 (last updated November 17, 2023)
An issue was discovered in dreamer_cms 4.1.3. There is a CSRF vulnerability that can delete a theme project via /admin/category/delete.
0
Attacker Value
Unknown
CVE-2023-48060
Disclosure Date: November 13, 2023 (last updated November 17, 2023)
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/task/add
0
Attacker Value
Unknown
CVE-2023-48058
Disclosure Date: November 13, 2023 (last updated November 17, 2023)
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/task/run
0
Attacker Value
Unknown
CVE-2023-45907
Disclosure Date: October 17, 2023 (last updated October 19, 2023)
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/variable/delete.
0
Attacker Value
Unknown
CVE-2023-45906
Disclosure Date: October 17, 2023 (last updated October 19, 2023)
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/user/add.
0