HIGH
GHSA-j63m-2vr6-fv7m
DevDojo Voyager vulnerable to path traversal
Details
DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/tcg/voyager
Introduced in:
0No fixed version published yet for tcg/voyager (composer). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-55415[ADVISORY]
- https://github.com/thedevdojo/voyager[PACKAGE]
- https://github.com/thedevdojo/voyager/blob/1.6/src/Http/Controllers/VoyagerCompassController.php#L213[WEB]
- https://github.com/thedevdojo/voyager/blob/1.6/src/Http/Controllers/VoyagerCompassController.php#L44[WEB]
- https://www.sonarsource.com/blog/the-tainted-voyage-uncovering-voyagers-vulnerabilities[WEB]