MEDIUM4.3
GHSA-35p2-5vrh-m3p6
DevDojo Voyager Arbitrary File Write
Details
DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user uploads a file via /admin/media/upload. An authenticated user can upload a web shell causing arbitrary code execution on the server.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/tcg/voyager
Introduced in:
0No fixed version published yet for tcg/voyager (composer). Pin to a known-safe version or switch to an alternative.