Executive brief
Interinfo DreamMaker, a development platform, contains a security flaw that allows authorized users with high-level privileges to upload malicious files. An attacker with administrative access could use this to install a web backdoor, granting them full control over the server. This could lead to the theft of sensitive data, complete service disruption, or further attacks on the internal network.
Technical details
An unrestricted file upload vulnerability (CWE-434) exists in Interinfo DreamMaker Java Composer version 2.2 and earlier. The flaw allows a remote attacker with high privileges (PR:H) to upload executable files, such as web shells, to the server. Because the application fails to properly validate or sanitize the uploaded file types, these files can be executed in the context of the web server, leading to full arbitrary code execution (RCE). Users are advised to update to Java Composer version 2.3 or later to remediate this issue.
Affected products
- Interinfo DreamMaker Java Composer 2.2 and earlier
Timeline
- 2026-05-29: disclosed
- 2026-05-29: advisory
- 2026-05-29: patched: Fixed in Java Composer 2.3