CVE-2024-55416
LOW NUCLEIDevDojo Voyager < 1.8.0 - Reflected Cross-Site Scripting via Compass Endpoint
Title source: llmExploitation Summary
CVE-2024-55416 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.
Description
DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By manipulating an authenticated user to click on a link, arbitrary Javascript can be executed.
Nuclei Templates (1)
DevDojo Voyager <=1.8.0 - Cross-Site Scripting
LOWVERIFIEDby iamnoooob,rootxharsh,pdresearch
Shodan:
title:"Voyager"
References (3)
Core 3
Core References
Product
https://github.com/thedevdojo/voyager/blob/1.6/src/Http/Controllers/VoyagerCompassController.php#L44
Exploit, Third Party Advisory
https://www.sonarsource.com/blog/the-tainted-voyage-uncovering-voyagers-vulnerabilities/
Scores
CVSS v3
3.5
EPSS
0.2385
EPSS Percentile
97.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (2)
tcg/voyager
0Packagist
thecontrolgroup/voyager
< 1.8.0
Published
Jan 30, 2025
Tracked Since
Feb 18, 2026