PT-2018-9597 · Traccar · Traccar Server
Published
2018-12-20
·
Updated
2019-01-07
·
CVE-2018-1000881
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Traccar Server versions 4.0 and earlier
Description:
The issue is related to a code injection vulnerability in the ComputedAttributesHandler.java file, which can lead to remote command execution. This can be exploited via a web application request by a self-registered user.
Recommendations:
For Traccar Server versions 4.0 and earlier, update to version 4.1 or later to resolve the issue.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Traccar Server