CVE-2026-85540
nicheAuthenticated SQL Injection in Interinfo DreamMaker
CVE-2026-85540 is a SQL injection flaw (CWE-89) in DreamMaker, the e-learning platform from Taiwanese vendor Interinfo, in which user-supplied input is incorporated into database queries without adequate sanitization. A remote attacker who already holds valid, low-privilege (authenticated) access to the platform can send crafted input that injects arbitrary SQL commands into those queries. Successful exploitation lets the attacker read, modify, or delete the platform's database contents, exposing or tampering with user accounts and training data — consistent with the CVSS 4.0 score of 8.7 (High), which reflects high confidentiality, integrity, and availability impact on the vulnerable system. Any organization running DreamMaker is potentially affected; deployments are concentrated among Taiwan-based organizations, and no specific affected version ranges have been published in the available data. Exploitation has not been observed: the flaw is not in CISA's KEV catalog, no public proof-of-concept exists, and EPSS estimates only a 0.3% probability of exploitation within 30 days.
What to do: Inventory your environment for Interinfo DreamMaker deployments and consult the TWCERT/CC advisory or the vendor for the affected version range and updated builds, then upgrade as soon as a patched release is available. Because exploitation requires an authenticated account, enforce strong credentials for platform users, run the database under a least-privilege account, and review web/application and database logs for anomalous SQL activity; a WAF rule blocking SQL-injection patterns on DreamMaker endpoints can reduce interim risk.
| Interinfo DreamMaker | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
DreamMaker developed by Interinfo has a SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.
- Weakness
- CWE-89
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.