Record summary

EIP currently links 1 Nuclei template to CVE-2024-55415.

Description

DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 30, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub AdvisoryThrough 1.8.0affected

Nuclei templates

1
ProjectDiscoveryHIGHDevDojo Voyager <=1.8.0 - Arbitrary File Read

DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass.

Impact

Authenticated attackers can exploit path traversal to read arbitrary files from the server, potentially exposing sensitive configuration files, credentials, and application source code.

Remediation

Update DevDojo Voyager to version 1.8.1 or later to address the path traversal vulnerability.

Authorsiamnoooob, rootxharsh, pdresearch
Template tagscvecve2024devdojovoyagerlfrlfivuln
Shodan: title:"Voyager"

Source: ProjectDiscovery

References

4