CVE-2024-55416
CVE-2024-55416: Reflected XSS vulnerability in DevDojo Voyager through 1.8.0 allows attackers to execute arbitrary JavaScript in a user's browser. This is achieved by tricking an authenticated user into clicking a malicious link targeting the /admin/compass endpoint. Although the CVSS score is 0, indicating minimal direct impact, the presence of reflected XSS should not be ignored. With an SVRS of 30, SOCRadar assesses the risk as moderate. Successful exploitation could lead to session hijacking, defacement, or unauthorized actions performed on behalf of the victim. While not immediately critical, organizations using DevDojo Voyager should prioritize patching or mitigating this vulnerability to prevent potential exploitation.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.