CVE-2024-55415
MEDIUM
Published 2025-01-30T00:00:00.000Z
Actions:
CVSS Score
V3.1
5.7
/10
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Base Score Metrics
Exploitability: N/A
Impact: N/A
Attack Vector Metrics
Impact Metrics
Description
DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass.
Available Exploits
DevDojo Voyager <=1.8.0 - Arbitrary File Read
DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass.
ID: CVE-2024-55415
Author: iamnoooobrootxharshpdresearch
High
References:
- https://www.sonarsource.com/blog/the-tainted-voyage-uncovering-voyagers-vulnerabilities/
- https://github.com/thedevdojo/voyager/blob/1.6/src/Http/Controllers/VoyagerCompassController.php#L213
- https://github.com/thedevdojo/voyager/blob/1.6/src/Http/Controllers/VoyagerCompassController.php#L44
- https://nvd.nist.gov/vuln/detail/CVE-2024-55415
Related News
No news articles found for this CVE.
References
Published: 2025-01-30T00:00:00.000Z
Last Modified: 2025-02-06T14:40:50.378Z
Copied to clipboard!