Reflected XSS Vulnerability in DevDojo Voyager Platform
CVE-2024-55416

3.5LOW

Key Information:

Vendor

DevDojo

Status
Vendor
CVE Published:
30 January 2025

What is CVE-2024-55416?

DevDojo Voyager, prior to version 1.8.0, is susceptible to a reflected Cross-Site Scripting (XSS) vulnerability. This issue arises when an authenticated user clicks on a specially crafted link, potentially leading to the execution of arbitrary JavaScript in the context of their session. Exploiting this vulnerability can compromise user data, manipulate session information, and facilitate further attacks on the application, highlighting the importance of secure coding practices and thorough input validation.

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.