Three security flaws in the open source PHP package Voyager have been discovered that an attacker could exploit to gain one-click remote execution of code on affected instances.
In a report published earlier this week, Yaniv Nizry, a Sonar researcher, said that attackers could execute arbitrary code if an authenticated Voyager clicks on a malicious hyperlink.
You can also find out more about the following: