Path Traversal Vulnerability in DevDojo Voyager Web Application
CVE-2024-55415

5.7MEDIUM

Key Information:

Vendor

DevDojo

Status
Vendor
CVE Published:
30 January 2025

What is CVE-2024-55415?

DevDojo Voyager, a popular web application framework, possesses a vulnerability that allows path traversal via the /admin/compass endpoint. This weakness can enable attackers to manipulate file paths and potentially access sensitive files outside the intended directory structure, posing a significant risk to server security. It is critical for users to evaluate their current version of Voyager and apply necessary updates to mitigate any associated risks. Developers and system administrators are encouraged to examine the code to prevent unauthorized data access and ensure robust security practices.

References

EPSS Score

27% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.