CVE-2024-55416
DevDojo Voyager vulnerable to reflected Cross-site Scripting
Record summary
EIP currently links 1 Nuclei template to CVE-2024-55416.
Description
DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By manipulating an authenticated user to click on a link, arbitrary Javascript can be executed.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 30, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
tcg/voyagerBrowse Packagist / tcg/voyager | GitHub Advisory | Through 1.8.0 | affected |
Nuclei templates
1ProjectDiscoveryLOWDevDojo Voyager <=1.8.0 - Cross-Site Scripting
DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By manipulating an authenticated user to click on a link, arbitrary Javascript can be executed.
Impact
Authenticated attackers can craft malicious links that execute arbitrary JavaScript in the context of an administrator's session when clicked, potentially leading to account compromise or privilege escalation.
Remediation
Update DevDojo Voyager to version 1.8.1 or later to address the reflected XSS vulnerability.
Source: ProjectDiscovery