CVE-2024-55417 affects DevDojo Voyager through version 1.8.0, allowing an authenticated user to bypass file type verification during media uploads. This enables the upload of a web shell, leading to arbitrary code execution on the server. The vulnerability has a CVSS score of 4.3 (MEDIUM), indicating a network-based attack with low privileges and complexity, primarily impacting integrity. While not yet in the KEV catalog, Nuclei templates exist for this high-severity flaw, and it has garnered community discussion and media coverage, including an article from BleepingComputer.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.8.0CPE matchmatch criteria | cpe:2.3:a:thecontrolgroup:voyager:*:*:*:*:*:laravel:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.