CVE-2024-55415 describes a path traversal vulnerability in DevDojo Voyager through version 1.8.0, specifically at the /admin/compass endpoint, affecting thecontrolgroup voyager product. This medium-severity vulnerability (CVSS 5.7) allows an authenticated attacker with low privileges to read arbitrary files, posing a high impact on confidentiality with low attack complexity. While not listed in KEV or Hot Lists, exploit intelligence indicates available Nuclei templates for arbitrary file read, and it has garnered significant community discussion and media coverage, including reports of a potential one-click RCE flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.8.0CPE matchmatch criteria | cpe:2.3:a:thecontrolgroup:voyager:*:*:*:*:*:laravel:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.