PT-2018-9597 · Traccar · Traccar Server

Published

2018-12-20

·

Updated

2019-01-07

·

CVE-2018-1000881

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Traccar Server versions 4.0 and earlier
Description: The issue is related to a code injection vulnerability in the ComputedAttributesHandler.java file, which can lead to remote command execution. This can be exploited via a web application request by a self-registered user.
Recommendations: For Traccar Server versions 4.0 and earlier, update to version 4.1 or later to resolve the issue.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1000881

Affected Products

Traccar Server