PT-2025-1306 · Devdojo · Devdojo Voyager

Yaniv Nizry

·

Published

2025-01-28

·

Updated

2025-05-23

·

CVE-2024-55417

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions DevDojo Voyager versions 1.8.0 and earlier
Description The issue allows an authenticated user to bypass file type verification when uploading a file via the "/admin/media/upload" endpoint. This can lead to the upload of a web shell, resulting in arbitrary code execution on the server. The vulnerability is being actively exploited.
Recommendations For DevDojo Voyager versions 1.8.0 and earlier, as a temporary workaround, consider disabling the file upload functionality via the "/admin/media/upload" endpoint until a patch is available. Restrict access to this endpoint to minimize the risk of exploitation. Avoid using this feature until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BDU:2025-00930
CVE-2024-55417
GHSA-35P2-5VRH-M3P6

Affected Products

Devdojo Voyager