7.2
CVSSv3

CVE-2019-17050

CVSSv4: NA | CVSSv3: 7.2 | CVSSv2: 6.5 | VMScore: 820 | EPSS: 0.00696 | KEV: Not Included
Published: 30/09/2019 Updated: 21/11/2024

Vulnerability Summary

An issue exists in the Voyager package up to and including 1.2.7 for Laravel. An attacker with admin privileges and Compass access can read or delete arbitrary files, such as the .env file. NOTE: a software maintainer has suggested a solution in which Compass is switched off in a production environment.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

thecontrolgroup voyager