dreamfactorysoftware/df-core

dreamfactorysoftware/df-core

Releases123
Frequency1 month 1 day
Last Release
Stars16
DreamFactory is a self-hosted platform providing governed API access to any data source for enterprise apps and local LLMs.

CVE History

CVEPublishedCVSS v3CVSS v2
7.2 HIGH

An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a directory traversal via an unsanitized URI path.

DreamFactory saveZipFile Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of DreamFactory. Authentication is required to exploit this vulnerability. The specific flaw exists within the implementation of the saveZipFile method. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-26589.