Path Traversal Vulnerability in iteachyou Dreamer CMS 4.1.3
CVE-2025-1543
Key Information:
- Vendor
- Iteachyou
- Status
- Dreamer Cms
- Vendor
- CVE Published:
- 21 February 2025
Badges
Summary
A path traversal vulnerability has been identified in iteachyou Dreamer CMS version 4.1.3, affecting the processing of the /resource/js/ueditor-1.4.3.3 file. This issue can be exploited remotely, allowing attackers to manipulate file paths and potentially access restricted directories. The vulnerability has been publicly disclosed, but the vendor has not provided any response regarding the matter. Users of this CMS should take immediate action to secure their installations and mitigate related risks.
Affected Version(s)
Dreamer CMS 4.1.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved