github.com
https://github.com/thedevdojo/voyager CVE-2024-55415
Nuclei
DevDojo Voyager vulnerable to path traversal
Record summary
EIP currently links 1 Nuclei template to CVE-2024-55415.
Description
DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 30, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
tcg/voyagerBrowse Packagist / tcg/voyager | GitHub Advisory | Through 1.8.0 | affected |
Nuclei templates
1ProjectDiscoveryHIGHDevDojo Voyager <=1.8.0 - Arbitrary File Read
DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass.
Impact
Authenticated attackers can exploit path traversal to read arbitrary files from the server, potentially exposing sensitive configuration files, credentials, and application source code.
Remediation
Update DevDojo Voyager to version 1.8.1 or later to address the path traversal vulnerability.
Authorsiamnoooob, rootxharsh, pdresearch
Template tagscvecve2024devdojovoyagerlfrlfivuln
Shodan: title:"Voyager"
https://www.sonarsource.com/blog/the-tainted-voyage-uncovering-voyagers-vulnerabilities/ https://github.com/thedevdojo/voyager/blob/1.6/src/Http/Controllers/VoyagerCompassController.php#L213 https://github.com/thedevdojo/voyager/blob/1.6/src/Http/Controllers/VoyagerCompassController.php#L44 https://nvd.nist.gov/vuln/detail/CVE-2024-55415
Source: ProjectDiscovery
References
4github.com
https://github.com/thedevdojo/voyager/blob/1.6/src/Http/Controllers/VoyagerCompassController.php nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-55415 sonarsource.com
https://www.sonarsource.com/blog/the-tainted-voyage-uncovering-voyagers-vulnerabilities