PT-2024-5771 · Traccar · Traccar

Nvn1729

·

Published

2024-04-10

·

Updated

2025-01-09

·

CVE-2024-31214

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Traccar versions 5.1 through 5.12
Description The issue allows arbitrary files to be uploaded through the device image upload API, giving attackers full control over the file contents, directory, and extension, and partial control over the file name. This can potentially lead to remote code execution, XSS, and DOS. The default installation of Traccar, with self-registration enabled and running with root/system privileges, makes this issue more severe.
Recommendations For Traccar versions 5.1 through 5.12, update to version 6.0 to resolve the issue. As a temporary workaround, consider turning off self-registration to reduce the severity of the vulnerability. Restrict access to the device image upload API to minimize the risk of exploitation.

Exploit

Fix

DoS

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-06484
CVE-2024-31214
GHSA-3GXQ-F2QJ-C8V9

Affected Products

Traccar