In Dreamer CMS before 4.0.1, the backend attachment management office has an Arbitrary File Download vulnerability.