• About
  • Disclaimer
  • Privacy Policy
  • Contact
Sunday, June 15, 2025
Cyber Defense GO
  • Login
  • Home
  • Cyber Security
  • Artificial Intelligence
  • Machine Learning
  • Data Analysis
  • Computer Networking
  • Disaster Restoration
No Result
View All Result
  • Home
  • Cyber Security
  • Artificial Intelligence
  • Machine Learning
  • Data Analysis
  • Computer Networking
  • Disaster Restoration
No Result
View All Result
Cyber Defense Go
No Result
View All Result
Home Cyber Security

Unpatched PHP Voyager Flaws Go away Servers Open to One-Click on RCE Exploits

Md Sazzad Hossain by Md Sazzad Hossain
0
Unpatched PHP Voyager Flaws Go away Servers Open to One-Click on RCE Exploits
585
SHARES
3.2k
VIEWS
Share on FacebookShare on Twitter


Jan 30, 2025Ravie LakshmananInternet Safety / Vulnerability

Unpatched PHP Voyager Flaws

Three safety flaws have been disclosed within the open-source PHP package deal Voyager that may very well be exploited by an attacker to realize one-click distant code execution on affected situations.

“When an authenticated Voyager consumer clicks on a malicious hyperlink, attackers can execute arbitrary code on the server,” Sonar researcher Yaniv Nizry mentioned in a write-up revealed earlier this week.

Cybersecurity

The recognized points, which stay unpatched up to now regardless of accountable disclosure on September 11, 2024, are listed beneath –

  • CVE-2024-55417 – An arbitrary file write vulnerability within the “/admin/media/add” endpoint
  • CVE-2024-55416 – A mirrored cross-site scripting (XSS) vulnerability within the “/admin/compass” endpoint
  • CVE-2024-55415 – An arbitrary file leak and deletion vulnerability

A malicious attacker may leverage Voyager’s media add function to add a malicious file in a way that bypasses MIME sort verification, and make use of a polyglot file that seems as a picture or video however incorporates executable PHP code to trick the server into processing it as a PHP script, thereby leading to distant code execution.

The vulnerability may be chained with CVE-2024-55416, elevating it right into a vital risk that results in code execution when a sufferer clicks on a malicious hyperlink.

Cybersecurity

“Which means that if an authenticated consumer clicks on a specifically crafted hyperlink, arbitrary JavaScript code will be executed,” Nizry defined. “Because of this, an attacker can carry out any subsequent motion within the context of the sufferer.”

CVE-2024-55415, alternatively, considerations a flaw within the file administration system that permits risk actors to wipe arbitrary information from the system, or exploit it at the side of the XSS vulnerability to extract the contents of the information.

Within the absence of a repair, customers are suggested to train warning when utilizing the venture of their functions.

Discovered this text fascinating? Comply with us on Twitter  and LinkedIn to learn extra unique content material we put up.



You might also like

Dutch police determine customers as younger as 11-year-old on Cracked.io hacking discussion board

Discord Invite Hyperlink Hijacking Delivers AsyncRAT and Skuld Stealer Concentrating on Crypto Wallets

Why Each Enterprise Wants a Regulatory & Compliance Lawyer—and the Proper IT Infrastructure to Assist Them

Tags: ExploitsFlawsLeaveOneClickopenPHPRCEServersUnpatchedVoyager
Previous Post

Meta’s AI invasion alerts dramatic shift for social media

Next Post

Nice Books for AI Engineering. 10 books with helpful insights about… | by Duncan McKinnon | Jan, 2025

Md Sazzad Hossain

Md Sazzad Hossain

Related Posts

Dutch police determine customers as younger as 11-year-old on Cracked.io hacking discussion board
Cyber Security

Dutch police determine customers as younger as 11-year-old on Cracked.io hacking discussion board

by Md Sazzad Hossain
June 15, 2025
Discord Invite Hyperlink Hijacking Delivers AsyncRAT and Skuld Stealer Concentrating on Crypto Wallets
Cyber Security

Discord Invite Hyperlink Hijacking Delivers AsyncRAT and Skuld Stealer Concentrating on Crypto Wallets

by Md Sazzad Hossain
June 14, 2025
The Carruth Knowledge Breach: What Oregon Faculty Staff Must Know
Cyber Security

Why Each Enterprise Wants a Regulatory & Compliance Lawyer—and the Proper IT Infrastructure to Assist Them

by Md Sazzad Hossain
June 14, 2025
Detecting Ransomware on Community: How Community Site visitors Evaluation Helps
Cyber Security

Detecting Ransomware on Community: How Community Site visitors Evaluation Helps

by Md Sazzad Hossain
June 13, 2025
What’s Zero Belief Structure? A Newbie’s Information
Cyber Security

What’s Zero Belief Structure? A Newbie’s Information

by Md Sazzad Hossain
June 13, 2025
Next Post
Nice Books for AI Engineering. 10 books with helpful insights about… | by Duncan McKinnon | Jan, 2025

Nice Books for AI Engineering. 10 books with helpful insights about… | by Duncan McKinnon | Jan, 2025

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Cease focusing on Russian hackers, Trump administration orders US Cyber Command

Cease focusing on Russian hackers, Trump administration orders US Cyber Command

March 4, 2025
Google DeepMind at ICLR 2024

Google DeepMind at ICLR 2024

March 22, 2025

Categories

  • Artificial Intelligence
  • Computer Networking
  • Cyber Security
  • Data Analysis
  • Disaster Restoration
  • Machine Learning

CyberDefenseGo

Welcome to CyberDefenseGo. We are a passionate team of technology enthusiasts, cybersecurity experts, and AI innovators dedicated to delivering high-quality, insightful content that helps individuals and organizations stay ahead of the ever-evolving digital landscape.

Recent

Detailed Comparability » Community Interview

Detailed Comparability » Community Interview

June 15, 2025
Dutch police determine customers as younger as 11-year-old on Cracked.io hacking discussion board

Dutch police determine customers as younger as 11-year-old on Cracked.io hacking discussion board

June 15, 2025

Search

No Result
View All Result

© 2025 CyberDefenseGo - All Rights Reserved

No Result
View All Result
  • Home
  • Cyber Security
  • Artificial Intelligence
  • Machine Learning
  • Data Analysis
  • Computer Networking
  • Disaster Restoration

© 2025 CyberDefenseGo - All Rights Reserved

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In