Executive brief
DreamMaker is a Java-based enterprise application development and deployment platform. This vulnerability allows authenticated attackers to execute arbitrary JavaScript code in users' browsers through malicious websites, potentially compromising user sessions, stealing sensitive data, or performing unauthorized actions on behalf of the victim.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in DreamMaker, specifically in the baServer3 servlet component. The vulnerability requires prior authentication and user interaction (clicking a malicious link) to exploit. An authenticated remote attacker can inject arbitrary JavaScript code that executes in a victim's browser within the context of the vulnerable application, allowing session hijacking, credential theft, or unauthorized operations. The vendor recommends updating to Java Composer Server 2.3 or disabling the baServer3 component entirely as a workaround.
Affected products
- Interinfo DreamMaker <2.3
Timeline
- 2026-09-04: disclosed