SQL Injection Vulnerability in DreamMaker by Interinfo
CVE-2026-85540
8.7HIGH
What is CVE-2026-85540?
DreamMaker, developed by Interinfo, is susceptible to SQL Injection, allowing authenticated remote attackers to execute arbitrary SQL queries. This vulnerability facilitates unauthorized access to sensitive database information, enabling the attacker to read, alter, or delete crucial data within the database. It underscores the necessity for robust input validation and regular patching to protect against such security risks.
Affected Version(s)
DreamMaker all
