Record summary

CVE-2024-55417 has a selected CVSS score of 4.3 (medium); EIP currently links 1 Nuclei template.

Description

DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user uploads a file via /admin/media/upload. An authenticated user can upload a web shell causing arbitrary code execution on the server.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 31, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub AdvisoryThrough 1.8.0affected

Nuclei templates

1
ProjectDiscoveryHIGHDevDojo Voyager <= 1.8.0 - Arbitrary File Write vulnerability

DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user uploads a file via /admin/media/upload. An authenticated user can upload a web shell causing arbitrary code execution on the server.

Impact

Authenticated attackers can bypass file type restrictions to upload PHP web shells, allowing arbitrary code execution on the server with web server privileges.

Remediation

Update DevDojo Voyager to version 1.8.1 or later to address the file upload validation bypass vulnerability.

Authorsiamnoooob, rootxharsh, pdresearch
Template tagscvecve2024intrusivedevdojovoyagerfile-uploadauthenticatedvuln
Shodan: title:"Voyager"

Source: ProjectDiscovery

References

4