CVE-2023-46886
CRITICALDreamer CMS <4.0.1 - Path Traversal
Title source: llmDescription
Dreamer CMS before version 4.0.1 is vulnerable to Directory Traversal. Background template management allows arbitrary modification of the template file, allowing system sensitive files to be read.
Exploits (1)
Scores
CVSS v3
9.1
EPSS
0.0059
EPSS Percentile
69.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Details
CWE
CWE-22
Status
published
Products (1)
iteachyou/dreamer_cms
< 4.0.1
Published
Nov 29, 2023
Tracked Since
Feb 18, 2026