An unrestricted upload of file with dangerous type vulnerability in the file upload function of Interinfo DreamMaker versions before 2025/10/22 allows remote attackers to execute arbitrary system commands via a malicious class file.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://zuso.ai/advisory/za-2026-02 |
|
History
Fri, 30 Jan 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unrestricted upload of file with dangerous type vulnerability in the file upload function of Interinfo DreamMaker versions before 2025/10/22 allows remote attackers to execute arbitrary system commands via a malicious class file. | |
| Title | Interinfo DreamMaker - Unrestricted Upload of File with Dangerous Type | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ZUSO ART
Published:
Updated: 2026-01-30T03:50:31.763Z
Reserved: 2026-01-26T07:42:53.160Z
Link: CVE-2026-24729
No data.
Status : Received
Published: 2026-01-30T05:16:33.490
Modified: 2026-01-30T05:16:33.490
Link: CVE-2026-24729
No data.
OpenCVE Enrichment
No data.