ZeroHour

CVE-2026-85540

niche

Authenticated SQL Injection in Interinfo DreamMaker

CVSS 4.0
8.7 high
EPSS
<1%p23
Published
()
Modified
AI analysis

CVE-2026-85540 is a SQL injection flaw (CWE-89) in DreamMaker, the e-learning platform from Taiwanese vendor Interinfo, in which user-supplied input is incorporated into database queries without adequate sanitization. A remote attacker who already holds valid, low-privilege (authenticated) access to the platform can send crafted input that injects arbitrary SQL commands into those queries. Successful exploitation lets the attacker read, modify, or delete the platform's database contents, exposing or tampering with user accounts and training data — consistent with the CVSS 4.0 score of 8.7 (High), which reflects high confidentiality, integrity, and availability impact on the vulnerable system. Any organization running DreamMaker is potentially affected; deployments are concentrated among Taiwan-based organizations, and no specific affected version ranges have been published in the available data. Exploitation has not been observed: the flaw is not in CISA's KEV catalog, no public proof-of-concept exists, and EPSS estimates only a 0.3% probability of exploitation within 30 days.

What to do: Inventory your environment for Interinfo DreamMaker deployments and consult the TWCERT/CC advisory or the vendor for the affected version range and updated builds, then upgrade as soon as a patched release is available. Because exploitation requires an authenticated account, enforce strong credentials for platform users, run the database under a least-privilege account, and review web/application and database logs for anomalous SQL activity; a WAF rule blocking SQL-injection patterns on DreamMaker endpoints can reduce interim risk.

Affected
Interinfo DreamMaker
Estimated exposure
nichelikely hundreds to low thousands of organizational deployments (Taiwan-market e-learning platform; no published install counts) — No active-install counts or internet-exposure scan data were provided, so the estimate rests on DreamMaker being a regional (Taiwan) enterprise e-learning platform deployed per organization rather than at mass-market consumer scale.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

DreamMaker developed by Interinfo has a SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.

Weakness
CWE-89
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.