Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-55417

31
FAUCET Score

CVE-2024-55417 affects DevDojo Voyager through version 1.8.0, allowing an authenticated user to bypass file type verification during media uploads. This enables the upload of a web shell, leading to arbitrary code execution on the server. The vulnerability has a CVSS score of 4.3 (MEDIUM), indicating a network-based attack with low privileges and complexity, primarily impacting integrity. While not yet in the KEV catalog, Nuclei templates exist for this high-severity flaw, and it has garnered community discussion and media coverage, including an article from BleepingComputer.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.8.0CPE matchmatch criteria
cpe:2.3:a:thecontrolgroup:voyager:*:*:*:*:*:laravel:*:*

CVSS Data

CVSS version used by this source: 3.1

4.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
13.22%
Probability of exploitation in next 30 days
EPSS Percentile
96.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
Nuclei: CVE-2024-55417 · Feb 5, 2025
This CVE's current EPSS score of 0.1322 is in the 99th percentile among its peer group of 21,954 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

composerGHSA-35p2-5vrh-m3p6medium

DevDojo Voyager Arbitrary File Write

Jan 30, 2025

References

github.com / thedevdojo/voyager/blob/1.6/src/Http/Controllers/VoyagerMediaController.php
Product
sonarsource.com / blog/the-tainted-voyage-uncovering-voyagers-vulnerabilities
ExploitThird Party Advisory