VDB
Sign up
CRITICAL9.1

GHSA-qq2h-m2hj-hrff

DevDojo Voyager Argument Injection vulnerability

Details

DevDojo Voyager 1.4.0 through 1.8.0, when Laravel 8 or later is used, allows authenticated administrators to execute arbitrary OS commands via a specific php artisan command.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/tcg/voyager
Introduced in: 1.4.0

No fixed version published yet for tcg/voyager (composer). Pin to a known-safe version or switch to an alternative.

References