CVE-2025-3977

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Apr 27, 2025
Updated: May 12, 2025
CWE ID 125

Summary

CVE-2025-3977 is a newly disclosed vulnerability affecting the iteachyou Dreamer CMS version 4.1.3. This issue poses a significant risk as an unknown functionality of the /admin/attachment/download component's Attachment Handler can be exploited. By manipulating the ID argument, attackers can bypass authorization checks, making it possible for them to gain unauthorized access. This vulnerability can be exploited remotely, increasing the threat level. The exploit for this issue has been made public, increasing the urgency for affected organizations to take action. Despite early disclosure, the vendor has not responded to address the vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share