A vulnerability was found in iteachyou Dreamer CMS 4.1.3. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/archives/edit. The manipulation of the argument editorValue/answer/content leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
History

Fri, 04 Apr 2025 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Iteachyou
Iteachyou dreamer Cms
Weaknesses CWE-918
CPEs cpe:2.3:a:iteachyou:dreamer_cms:4.1.3:*:*:*:*:*:*:*
Vendors & Products Iteachyou
Iteachyou dreamer Cms

Fri, 21 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in iteachyou Dreamer CMS 4.1.3. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/archives/edit. The manipulation of the argument editorValue/answer/content leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title iteachyou Dreamer CMS edit cross site scripting
Weaknesses CWE-79
CWE-94
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-02-21T17:00:10.190Z

Updated: 2025-02-21T20:49:11.366Z

Reserved: 2025-02-21T10:38:37.750Z

Link: CVE-2025-1548

cve-icon Vulnrichment

Updated: 2025-02-21T20:49:05.742Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-21T17:15:13.897

Modified: 2025-04-04T16:40:52.380

Link: CVE-2025-1548

cve-icon Redhat

No data.