{ "id": "CVE-2024-55416", "sourceIdentifier": "cve@mitre.org", "published": "2025-01-30T15:15:17.583", "lastModified": "2025-01-30T15:15:17.583", "vulnStatus": "Received", "cveTags": [], "descriptions": [ { "lang": "en", "value": "DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By manipulating an authenticated user to click on a link, arbitrary Javascript can be executed." } ], "metrics": {}, "references": [ { "url": "https://github.com/thedevdojo/voyager/blob/1.6/resources/views/master.blade.php#L132", "source": "cve@mitre.org" }, { "url": "https://github.com/thedevdojo/voyager/blob/1.6/src/Http/Controllers/VoyagerCompassController.php#L44", "source": "cve@mitre.org" }, { "url": "https://www.sonarsource.com/blog/the-tainted-voyage-uncovering-voyagers-vulnerabilities/", "source": "cve@mitre.org" } ] }