
Cloud Vulnerability DB
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
DevDojo Voyager through version 1.8.0 contains a reflected Cross-Site Scripting (XSS) vulnerability in the /admin/compass endpoint. The vulnerability was discovered in January 2025 and affects the Laravel admin package that has over 11,800 stars on GitHub and millions of downloads (Bleeping Computer, Hacker News).
The vulnerability exists in the /admin/compass endpoint where user input is improperly sanitized, allowing attackers to inject JavaScript into popup messages. When an authenticated admin clicks on a malicious link, the script executes in their browser. The vulnerability received a CVSS v3.1 Base Score of 3.5 (LOW) with vector string CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N (NVD).
When exploited, the vulnerability allows attackers to perform actions on behalf of authenticated administrators, potentially escalating to remote code execution. The vulnerability becomes particularly dangerous when chained with other vulnerabilities in the system, enabling attackers to execute arbitrary code on the server when a privileged user clicks on a malicious link (Sonar Source).
At the time of disclosure, no official patches are available for this vulnerability. Users are advised to restrict access to trusted users only, implement strict role-based access control (RBAC), and consider avoiding the use of Voyager in production environments until official patches are released (Bleeping Computer).
The vulnerability was initially discovered by SonarSource researchers who attempted to report it to Voyager maintainers multiple times since September 11, 2024. After receiving no response within the 90-day disclosure window, the researchers publicly disclosed the vulnerability to protect users (Sonar Source).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques
A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation
Get a personalized demo
“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
“We know that if Wiz identifies something as critical, it actually is.”