A vulnerability was found in Dreamer CMS up to 4.1.3. It has been declared as problematic. This vulnerability affects the function updatePwd of the file UserController.java of the component Password Hash Calculation. The manipulation leads to inefficient algorithmic complexity. The attack can be initiated remotely. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-227860.
History

Fri, 04 Apr 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Iteachyou
Iteachyou dreamer Cms
CPEs cpe:2.3:a:dreamer_cms_project:dreamer_cms:*:*:*:*:*:*:*:* cpe:2.3:a:iteachyou:dreamer_cms:*:*:*:*:*:*:*:*
Vendors & Products Dreamer Cms Project
Dreamer Cms Project dreamer Cms
Iteachyou
Iteachyou dreamer Cms

Thu, 30 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2023-05-02T12:00:09.669Z

Updated: 2025-01-30T14:16:41.817Z

Reserved: 2023-05-02T11:43:40.581Z

Link: CVE-2023-2473

cve-icon Vulnrichment

Updated: 2024-08-02T06:26:08.525Z

cve-icon NVD

Status : Modified

Published: 2023-05-02T13:15:25.090

Modified: 2025-04-04T15:16:10.910

Link: CVE-2023-2473

cve-icon Redhat

No data.