PT-2024-13959 · Traccar · Traccar

Isacaya

·

Published

2024-01-15

·

Updated

2024-01-19

·

CVE-2023-50729

CVSS v3.1

8.4

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Traccar versions prior to 5.11
Description Traccar, an open source GPS tracking system, is affected by an unrestricted file upload vulnerability in the File feature. This allows attackers to execute arbitrary code on the server. The issue is more prevalent due to the recommendation to run Traccar web servers as the root user, making it more dangerous as it can write or overwrite files in arbitrary locations.
Recommendations For versions prior to 5.11, update to version 5.11 to fix the vulnerability. As a temporary workaround, consider restricting access to the File feature until the update is applied.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2023-50729
GHSA-PQF7-8G85-VX2Q

Affected Products

Traccar