Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Yiliufeng168

#30863of 53,635
8.5Total CVSS
Vulnerabilities · 1
PT-2024-20577
8.5
2024-04-10
Traccar · Traccar · CVE-2024-24809
**Name of the Vulnerable Software and Affected Versions** Traccar versions prior to 6.0 **Description** Traccar is an open source GPS tracking system. The issue allows for path traversal and unrestricted upload of files with dangerous types. Since the system allows registration by default, attackers can acquire ordinary user permissions by registering an account and exploit this vulnerability to upload files with the prefix `device.` under any folder. This can be used for phishing, cross-site scripting attacks, and potentially execute arbitrary commands on the server. **Recommendations** For versions prior to 6.0, update to version 6.0 to resolve the issue. As a temporary workaround, consider restricting the ability for new users to register or limiting the upload functionality to prevent exploitation. Restrict access to the file upload feature to minimize the risk of uploading malicious files.