CVE detail
CVE-2020-13533 — CVE-2020-13533
Published 2021-04-09 · Modified 2026-06-17 · Vendor dreamreport · Product dream_report · Source nvd
HIGH
severity
CVSS-derived band
0.0042
EPSS probability
exploitation probability, 30d
35.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A privilege escalation vulnerability exists in Dream Report 5 R20-2. IIn the default configuration, the following registry keys, which reference binaries with weak permissions, can be abused by attackers to effectively ‘backdoor’ the installation files and escalate privileges when a new user logs in and uses the application.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References