LOW
GHSA-mm49-4f2g-c3wf
DevDojo Voyager vulnerable to reflected Cross-site Scripting
Details
DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By manipulating an authenticated user to click on a link, arbitrary Javascript can be executed.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/tcg/voyager
Introduced in:
0No fixed version published yet for tcg/voyager (composer). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-55416[ADVISORY]
- https://github.com/thedevdojo/voyager[PACKAGE]
- https://github.com/thedevdojo/voyager/blob/1.6/resources/views/master.blade.php#L132[WEB]
- https://github.com/thedevdojo/voyager/blob/1.6/src/Http/Controllers/VoyagerCompassController.php#L44[WEB]
- https://www.sonarsource.com/blog/the-tainted-voyage-uncovering-voyagers-vulnerabilities[WEB]