An access control issue in Dreamer CMS v4.0.1 allows attackers to download backup files and leak sensitive information.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://github.com/Fei123-design/vuln/blob/master/Dreamer%20CMS%20Unauthorized%20access%20vulnerability.md | third party advisory exploit |