RULE(RULE ID:338695)

Rule General Information
Release Date: 2025-02-18
Rule Name: DevDojo Voyager 1.8.0 Arbitrary File Read vulnerability (CVE-2024-55415)
Severity:
CVE ID:
Rule Protection Details
Description: DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference: https://github.com/thedevdojo/voyager/blob/1.6/src/Http/Controllers/VoyagerCompassController.php#L213
https://github.com/thedevdojo/voyager/blob/1.6/src/Http/Controllers/VoyagerCompassController.php#L44
https://www.sonarsource.com/blog/the-tainted-voyage-uncovering-voyagers-vulnerabilities/
Solutions
Please contact the software vendor to update the software patch.