Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

I6Who7Dreamer

#38387of 56,330
7.5Total CVSS
Vulnerabilities · 1
PT-2023-19753
7.5
2023-05-02
Unknown · Dreamer Cms · CVE-2023-2473
**Name of the Vulnerable Software and Affected Versions** Dreamer CMS versions up to 4.1.3 **Description** A vulnerability was found in the Password Hash Calculation component, specifically affecting the `updatePwd` function of the `UserController.java` file. This issue leads to inefficient algorithmic complexity and can be initiated remotely. **Recommendations** For Dreamer CMS versions up to 4.1.3, it is recommended to upgrade the affected component to resolve the issue. As a temporary workaround, consider restricting access to the `updatePwd` function of the `UserController.java` file until an upgrade is possible.