Description
Traccar is an open source GPS tracking system. Prior to 5.11, Traccar is affected by an unrestricted file upload vulnerability in File feature allows attackers to execute arbitrary code on the server. This vulnerability is more prevalent because Traccar is recommended to run web servers as root user. It is also more dangerous because it can write or overwrite files in arbitrary locations. Version 5.11 was published to fix this vulnerability.
References (1)
Core 1
Core References
Third Party Advisory x_refsource_confirm
https://github.com/traccar/traccar/security/advisories/GHSA-pqf7-8g85-vx2q
Scores
CVSS v3
8.4
EPSS
0.0007
EPSS Percentile
21.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-434
Status
published
Products (1)
traccar/traccar
< 5.11
Published
Jan 15, 2024
Tracked Since
Feb 18, 2026