📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Artificial Intelligence and Technology HIGH 2h Global general Technology and Artificial Intelligence MEDIUM 5h Global general Technology and Artificial Intelligence HIGH 6h Global vulnerability Higher Education CRITICAL 15h Global data_breach Government HIGH 16h Global supply_chain Software Development and Open Source Communities CRITICAL 16h Global malware Software Development CRITICAL 16h Global phishing Multiple Sectors HIGH 17h Global vulnerability Web Applications CRITICAL 17h Global apt Critical Infrastructure CRITICAL 17h Global vulnerability Artificial Intelligence and Technology HIGH 2h Global general Technology and Artificial Intelligence MEDIUM 5h Global general Technology and Artificial Intelligence HIGH 6h Global vulnerability Higher Education CRITICAL 15h Global data_breach Government HIGH 16h Global supply_chain Software Development and Open Source Communities CRITICAL 16h Global malware Software Development CRITICAL 16h Global phishing Multiple Sectors HIGH 17h Global vulnerability Web Applications CRITICAL 17h Global apt Critical Infrastructure CRITICAL 17h Global vulnerability Artificial Intelligence and Technology HIGH 2h Global general Technology and Artificial Intelligence MEDIUM 5h Global general Technology and Artificial Intelligence HIGH 6h Global vulnerability Higher Education CRITICAL 15h Global data_breach Government HIGH 16h Global supply_chain Software Development and Open Source Communities CRITICAL 16h Global malware Software Development CRITICAL 16h Global phishing Multiple Sectors HIGH 17h Global vulnerability Web Applications CRITICAL 17h Global apt Critical Infrastructure CRITICAL 17h
Vulnerabilities

CVE-2020-37214

High
Voyager 1.3.0 contains a directory traversal vulnerability that allows attackers to access sensitive system files by manipulating the asset path parameter. Attackers can exploit the path parameter in
CWE-22 — Weakness Type
Published: Feb 11, 2026  ·  Modified: Feb 28, 2026  ·  Source: NVD
CVSS v3
7.5
🔗 NVD Official
📄 Description (English)

Voyager 1.3.0 contains a directory traversal vulnerability that allows attackers to access sensitive system files by manipulating the asset path parameter. Attackers can exploit the path parameter in /admin/voyager-assets to read arbitrary files like /etc/passwd and .env configuration files.

🤖 AI Executive Summary

CVE-2020-37214 is a directory traversal vulnerability in Voyager 1.3.0 that allows unauthenticated attackers to read arbitrary files including sensitive system configurations and credentials through the /admin/voyager-assets endpoint. With a CVSS score of 7.5, this vulnerability poses a significant risk to organizations using Voyager for content management, potentially exposing database credentials, API keys, and system information. Immediate patching is critical as the vulnerability requires minimal technical sophistication to exploit.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 1, 2026 11:01
🇸🇦 Saudi Arabia Impact Assessment
Saudi organizations using Voyager CMS for government portals, banking websites, healthcare information systems, and e-commerce platforms are at significant risk. Government agencies under NCA oversight, SAMA-regulated financial institutions, and healthcare providers managing patient data face critical exposure of sensitive information. Telecommunications companies and energy sector organizations using Voyager for administrative interfaces could have their infrastructure credentials compromised. The vulnerability's ability to expose .env files containing database credentials and API keys makes it particularly dangerous for organizations handling Saudi citizen data subject to PDPL compliance requirements.
🏢 Affected Saudi Sectors
Government Banking and Financial Services Healthcare Energy and Utilities Telecommunications E-commerce Education
⚖️ Saudi Risk Score (AI)
8.2
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all systems running Voyager 1.3.0 and isolate them from production networks if possible
2. Review access logs for /admin/voyager-assets endpoint for suspicious path traversal attempts (patterns like ../, ..\, encoded variants)
3. Assume compromise of any .env files and database credentials — rotate all database passwords, API keys, and service account credentials immediately
4. Check for unauthorized access to /etc/passwd, /etc/shadow, configuration files, and application source code

PATCHING:
1. Upgrade Voyager to version 1.3.1 or later immediately
2. Apply vendor security patches through your package manager (composer update voyager)
3. Verify patch installation by confirming version number and checking for path traversal filtering in asset handling code

COMPENSATING CONTROLS (if immediate patching impossible):
1. Implement Web Application Firewall (WAF) rules to block requests containing ../, ..\, %2e%2e, and URL-encoded traversal sequences to /admin/voyager-assets
2. Restrict /admin/voyager-assets endpoint to specific IP ranges and require additional authentication
3. Disable directory listing and implement strict file access controls
4. Move sensitive configuration files (.env) outside web root

DETECTION:
1. Monitor for HTTP requests to /admin/voyager-assets with path traversal patterns
2. Alert on access attempts to sensitive files: /etc/passwd, /etc/shadow, .env, config files
3. Log and review all 200 responses from /admin/voyager-assets endpoint
4. Implement IDS/IPS signatures for directory traversal attacks (CWE-22)
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع الأنظمة التي تعمل بـ Voyager 1.3.0 وعزلها عن شبكات الإنتاج إن أمكن
2. مراجعة سجلات الوصول لنقطة النهاية /admin/voyager-assets للبحث عن محاولات اجتياز مريبة (أنماط مثل ../ و ..\)
3. افترض اختراق ملفات .env وبيانات اعتماد قاعدة البيانات — قم بتدوير جميع كلمات مرور قواعد البيانات ومفاتيح API فوراً
4. تحقق من الوصول غير المصرح به إلى /etc/passwd والملفات الحساسة الأخرى

التصحيح:
1. قم بترقية Voyager إلى الإصدار 1.3.1 أو أحدث فوراً
2. طبق تصحيحات الأمان من خلال مدير الحزم (composer update voyager)
3. تحقق من تثبيت التصحيح بتأكيد رقم الإصدار والتحقق من تصفية اجتياز المسار

الضوابط البديلة:
1. تطبيق قواعد جدار حماية تطبيقات الويب لحجب الطلبات التي تحتوي على أنماط اجتياز المسار
2. تقييد نقطة النهاية /admin/voyager-assets على نطاقات IP محددة
3. تعطيل قائمة المجلدات وتطبيق ضوابط وصول صارمة
4. نقل ملفات التكوين الحساسة خارج جذر الويب

الكشف:
1. مراقبة طلبات HTTP إلى /admin/voyager-assets بأنماط اجتياز المسار
2. تنبيهات محاولات الوصول إلى الملفات الحساسة
3. تسجيل ومراجعة جميع الاستجابات من نقطة النهاية
4. تطبيق توقيعات IDS/IPS لهجمات اجتياز المجلدات
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
A.5.1.1 - Information security policies and procedures A.6.1.1 - Access control policy A.8.1.1 - Asset management policy A.12.2.1 - Change management procedures A.12.6.1 - Management of technical vulnerabilities
🔵 SAMA CSF
ID.AM-2 - Software inventory and management PR.AC-1 - Access control policy and procedures PR.PT-2 - Removable media protection DE.CM-1 - Network monitoring RS.MI-2 - Incident response and management
🟡 ISO 27001:2022
A.5.1 - Management direction for information security A.6.1 - Internal organization A.8.1 - Asset responsibility A.12.2 - Change management A.12.6 - Management of technical vulnerabilities A.14.2 - Development and change management
🟣 PCI DSS v4.0.1
Requirement 2.2 - Configuration standards Requirement 6.2 - Security patches Requirement 6.5.1 - Injection flaws Requirement 11.2 - Vulnerability scanning
📊 CVSS Score
7.5
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityN — None / Network
AvailabilityN — None / Network
📋 Quick Facts
Severity High
CVSS Score7.5
CWECWE-22
EPSS0.30%
Exploit No
Patch ✓ Yes
Published 2026-02-11
Source Feed nvd
Views 5
🇸🇦 Saudi Risk Score
8.2
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
CWE-22
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.