PT-2024-5771 · Traccar · Traccar
Nvn1729
·
Published
2024-04-10
·
Updated
2025-01-09
·
CVE-2024-31214
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Traccar versions 5.1 through 5.12
Description
The issue allows arbitrary files to be uploaded through the device image upload API, giving attackers full control over the file contents, directory, and extension, and partial control over the file name. This can potentially lead to remote code execution, XSS, and DOS. The default installation of Traccar, with self-registration enabled and running with root/system privileges, makes this issue more severe.
Recommendations
For Traccar versions 5.1 through 5.12, update to version 6.0 to resolve the issue.
As a temporary workaround, consider turning off self-registration to reduce the severity of the vulnerability.
Restrict access to the device image upload API to minimize the risk of exploitation.
Exploit
Fix
DoS
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Traccar