Common vulnerabilities and Exposures (CVE)

Skip to main content

Required CVE Record Information

Description

DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user uploads a file via /admin/media/upload. An authenticated user can upload a web shell causing arbitrary code execution on the server.

Authorized Data Publishers