CVE-2024-55417: Thecontrolgroup Voyager
Medium severity, CVSS 4.3. EPSS: 14.1% chance of exploitation in the next 30 days.
DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user uploads a file via /admin/media/upload. An authenticated user can upload a web shell causing arbitrary code execution on the server.
Affected products
- Thecontrolgroup Voyager: up to and including 1.8.0
Published 2025-01-30. Last modified 2026-06-17.