Executive brief
Interinfo DreamMaker, a development platform, contains a critical security flaw that allows unauthorized individuals to upload malicious files to the server. By exploiting this vulnerability, an attacker can gain full control over the system, potentially leading to the theft of sensitive data, service disruption, or the installation of ransomware. This issue can be triggered remotely without any valid login credentials.
Technical details
An arbitrary file upload vulnerability (CWE-434) exists in Interinfo DreamMaker Java Composer versions 2.2 and earlier. The flaw allows an unauthenticated remote attacker to upload files with dangerous extensions to the server. By uploading a web shell or similar backdoor, the attacker can achieve remote code execution (RCE) with the privileges of the web service. The vulnerability is exploitable over the network without user interaction. Users are advised to update to Java Composer version 2.3 or later to mitigate this risk.
Affected products
- Interinfo DreamMaker Java Composer 2.2 and earlier
Timeline
- 2026-05-29: disclosed
- 2026-05-29: advisory
- 2026-05-29: patched: Update to Java Composer 2.3 or later