In Dreamer CMS before 4.0.1, the backend attachment management office has an Arbitrary File Download vulnerability.
The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.
Link | Tags |
---|---|
https://gitee.com/iteachyou/dreamer_cms/issues/I6NDEZ | issue tracking exploit |