Unfixed PHP Voyager Vulnerabilities Expose Servers to One-Click Remote Code Execution Attacks
A trio of security vulnerabilities have been revealed in the freely available PHP software Voyager that may be leveraged by a malicious actor to gain one-click access to executing code remotely on impacted systems. “By clicking on a nefarious link, a logged-in Voyager user enables threat actors to run any code on the server,” noted Yaniv Nizry, a researcher at Sonar, in a recent report.
