Record summary

EIP currently links 1 Nuclei template to CVE-2024-55416.

Description

DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By manipulating an authenticated user to click on a link, arbitrary Javascript can be executed.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 30, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub AdvisoryThrough 1.8.0affected

Nuclei templates

1
ProjectDiscoveryLOWDevDojo Voyager <=1.8.0 - Cross-Site Scripting

DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By manipulating an authenticated user to click on a link, arbitrary Javascript can be executed.

Impact

Authenticated attackers can craft malicious links that execute arbitrary JavaScript in the context of an administrator's session when clicked, potentially leading to account compromise or privilege escalation.

Remediation

Update DevDojo Voyager to version 1.8.1 or later to address the reflected XSS vulnerability.

Authorsiamnoooob, rootxharsh, pdresearch
Template tagscvecve2024devdojoxssauthenticatedvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
Shodan: title:"Voyager"

Source: ProjectDiscovery

References

5