CVE-2025-3977 | iteachyou Dreamer CMS up to 4.1.3 Attachment download ID improper authorization (IC13O1)
A vulnerability was found in iteachyou Dreamer CMS up to 4.1.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/attachment/download of the component Attachment Handler. The manipulation of the argument ID leads to improper authorization.
This vulnerability is known as CVE-2025-3977. The attack can be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.