A missing authentication for critical function vulnerability in the /servlet/baServer3 endpoint of Interinfo DreamMaker versions before 2025/10/22 allows remote attackers to access exposed administrative functionality without prior authentication.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://zuso.ai/advisory/za-2026-01 |
|
History
Fri, 30 Jan 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A missing authentication for critical function vulnerability in the /servlet/baServer3 endpoint of Interinfo DreamMaker versions before 2025/10/22 allows remote attackers to access exposed administrative functionality without prior authentication. | |
| Title | Interinfo DreamMaker - Missing Authentication for Critical Function | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ZUSO ART
Published:
Updated: 2026-01-30T03:48:28.100Z
Reserved: 2026-01-26T07:42:53.160Z
Link: CVE-2026-24728
No data.
Status : Received
Published: 2026-01-30T05:16:33.347
Modified: 2026-01-30T05:16:33.347
Link: CVE-2026-24728
No data.
OpenCVE Enrichment
No data.