CVE-2019-17050

HIGH EXPLOITED

Thecontrolgroup Voyager < 1.2.7 - IDOR

Title source: rule
STIX 2.1

Description

An issue was discovered in the Voyager package through 1.2.7 for Laravel. An attacker with admin privileges and Compass access can read or delete arbitrary files, such as the .env file. NOTE: a software maintainer has suggested a solution in which Compass is switched off in a production environment.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://github.com/the-control-group/voyager/issues/4322

Scores

CVSS v3 7.2
EPSS 0.0056
EPSS Percentile 68.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2025-04-29
CWE
CWE-639
Status published
Products (1)
thecontrolgroup/voyager < 1.2.7
Published Sep 30, 2019
Tracked Since Feb 18, 2026