Vulnerabilities
Vulnerable Software
Iteachyou:  >> Dreamer Cms  Security Vulnerabilities
An issue was discovered in dreamer_cms 4.1.3. There is a CSRF vulnerability that can delete a theme project via /admin/category/delete.
CVSS Score
4.3
EPSS Score
0.001
Published
2023-11-13
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin\/category\/add.
CVSS Score
8.8
EPSS Score
0.001
Published
2023-10-17
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/attachment/delete.
CVSS Score
8.8
EPSS Score
0.001
Published
2023-10-17
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/label/delete.
CVSS Score
8.8
EPSS Score
0.001
Published
2023-10-17
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /variable/update.
CVSS Score
8.8
EPSS Score
0.001
Published
2023-10-17
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/variable/add.
CVSS Score
8.8
EPSS Score
0.001
Published
2023-10-17
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/user/add.
CVSS Score
8.8
EPSS Score
0.001
Published
2023-10-17
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/variable/delete.
CVSS Score
8.8
EPSS Score
0.001
Published
2023-10-17
Dreamer CMS v4.1.3 was discovered to contain an arbitrary file read vulnerability via the component /admin/TemplateController.java.
CVSS Score
7.5
EPSS Score
0.002
Published
2023-09-27
Dreamer CMS v4.1.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component /admin/u/toIndex.
CVSS Score
5.4
EPSS Score
0.003
Published
2023-09-27


Contact Us

Shodan ® - All rights reserved