CVE-2026-10072 PUBLISHED

Interinfo|DreamMaker - Arbitrary File Upload

Assigner: twcert
Reserved: 29.05.2026 Published: 29.05.2026 Updated: 29.05.2026

DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.6

Product Status

Vendor Interinfo
Product DreamMaker
Versions Default: unaffected
  • affected from 0 to Java Composer 2.2 (incl.)

Solutions

Update to version Java Composer 2.3 or later

References

Problem Types

  • CWE-434 Unrestricted upload of file with dangerous type CWE

Impacts

  • CAPEC-650 Upload a Web Shell to a Web Server