Traccar vulnerable to Path Traversal: 'dir/../../filename' and Unrestricted Upload of File with Dangerous Type
48Vexday Risk Score
Corrija em breve. Ela tem exploit funcional público.
ssvc Attendcvss 8.5epss 54%
da publicação à arma135 dias
Publicada no NVD10 de abr.
metasploit+135d
probabilidade de exploração
54%top 1% das CVEs
exploração observada
nãonenhuma fonte reporta
Traccar is an open source GPS tracking system. Versions prior to 6.0 are vulnerable to path traversal and unrestricted upload of file with dangerous type. Since the system allows registration by default, attackers can acquire ordinary user permissions by registering an account and exploit this vulnerability to upload files with the prefix `device.` under any folder. Attackers can use this vulnerability for phishing, cross-site scripting attacks, and potentially execute arbitrary commands on the server. Version 6.0 contains a patch for the issue.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L
Produtos afetados
traccar · traccar