Skip to content

lishihihi/voyager-issue-report

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 

Repository files navigation

Security Advisory for DevDojo Voyager

Description

DevDojo Voyager versions 1.4.0 through 1.8.0 are vulnerable to command injection at the /admin/compass endpoint.
An authenticated administrator can execute arbitrary system commands due to improper input handling.

Affected Versions

Impacted: 1.4.0 - 1.8.0 (running on Laravel 8 and later)

Recommendation

🔹 Disable the Compass feature (/admin/compass) if not required.

POC

voyager-rce-poc

About

Security advisory for a vulnerability in DevDojo Voyager

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors