CVE-2024-55417
33Vexday Risk Score
Corrige pronto. Ella tiene exploit funcional público.
ssvc Attendcvss 4.3epss 14%
probabilidad de explotación
14%top 4% de las CVE
explotación observada
noninguna fuente lo reporta
DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user uploads a file via /admin/media/upload. An authenticated user can upload a web shell causing arbitrary code execution on the server.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Productos afectados
n/a · n/a