DreamMaker developed by Interinfo has a SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.
Advisories
No advisories yet.
Fixes
Solution
Using SQLBuilder Component
Workaround
No workaround given by the vendor.
References
History
Fri, 04 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Interinfo
Interinfo dreammaker |
|
| Vendors & Products |
Interinfo
Interinfo dreammaker |
Fri, 04 Sep 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DreamMaker developed by Interinfo has a SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Title | Interinfo|DreamMaker - SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2026-09-04T09:34:46.643Z
Reserved: 2026-09-04T09:08:31.657Z
Link: CVE-2026-85540
No data.
Status : Received
Published: 2026-09-04T10:17:14.017
Modified: 2026-09-04T10:17:14.017
Link: CVE-2026-85540
No data.
OpenCVE Enrichment
Updated: 2026-09-04T10:30:17Z
Weaknesses