DevDojo Voyager Arbitrary File Write
Moderate severity
GitHub Reviewed
Published
Jan 30, 2025
to the GitHub Advisory Database
•
Updated Feb 6, 2025
Description
Published by the National Vulnerability Database
Jan 30, 2025
Published to the GitHub Advisory Database
Jan 30, 2025
Last updated
Feb 6, 2025
Reviewed
Feb 6, 2025
DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user uploads a file via /admin/media/upload. An authenticated user can upload a web shell causing arbitrary code execution on the server.
References