CVE-2024-55417

DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user uploads a file via /admin/media/upload. An authenticated user can upload a web shell causing arbitrary code execution on the server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:thecontrolgroup:voyager:*:*:*:*:*:laravel:*:*

History

No history.

Information

Published : 2025-01-30 15:15

Updated : 2025-05-23 16:24


NVD link : CVE-2024-55417

Mitre link : CVE-2024-55417

CVE.ORG link : CVE-2024-55417


JSON object : View

Products Affected

thecontrolgroup

  • voyager
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type