CVE-2023-46887
HIGHDreamer CMS <4.0.1 - Info Disclosure
Title source: llmDescription
In Dreamer CMS before 4.0.1, the backend attachment management office has an Arbitrary File Download vulnerability.
Exploits (1)
Scores
CVSS v3
7.5
EPSS
0.0017
EPSS Percentile
37.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-494
Status
published
Products (1)
iteachyou/dreamer_cms
< 4.0.1
Published
Nov 29, 2023
Tracked Since
Feb 18, 2026