PT-2024-13959 · Traccar · Traccar
Isacaya
·
Published
2024-01-15
·
Updated
2024-01-19
·
CVE-2023-50729
CVSS v3.1
8.4
High
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Traccar versions prior to 5.11
Description
Traccar, an open source GPS tracking system, is affected by an unrestricted file upload vulnerability in the File feature. This allows attackers to execute arbitrary code on the server. The issue is more prevalent due to the recommendation to run Traccar web servers as the root user, making it more dangerous as it can write or overwrite files in arbitrary locations.
Recommendations
For versions prior to 5.11, update to version 5.11 to fix the vulnerability. As a temporary workaround, consider restricting access to the File feature until the update is applied.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Traccar