vendor:
Voyager
by:
NgoAnhDuc
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Voyager
Affected Version From: 1.3.0
Affected Version To: 1.3.0
Patch Exists: YES
Related CWE: N/A
CPE: a:the_control_group:voyager
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 18.04
2020
Voyager 1.3.0 – Directory Traversal
Voyager 1.3.0 and bellow is vulnerable to Directory Traversal. The vulnerability exists due to insufficient sanitization of user-supplied input in the 'path' parameter of the '/admin/voyager-assets' URL. A remote attacker can send a specially crafted request to the vulnerable application and gain access to arbitrary files on the server, including the Laravel environment file. This can lead to further attacks such as remote code execution.
Mitigation:
Upgrade to version 1.3.1 or later.