Vulnerability Description
Traccar Traccar Server version 4.0 and earlier contains a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in ComputedAttributesHandler.java that can result in Remote Command Execution. This attack appear to be exploitable via Remote: web application request by a self-registered user. This vulnerability appears to have been fixed in 4.1 and later.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Traccar | Server | <= 4.0 |
Related Weaknesses (CWE)
References
- https://appcheck-ng.com/advisory-remote-code-execution-traccar-server/ExploitThird Party Advisory
- https://appcheck-ng.com/advisory-remote-code-execution-traccar-server/ExploitThird Party Advisory
FAQ
What is CVE-2018-1000881?
CVE-2018-1000881 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Traccar Traccar Server version 4.0 and earlier contains a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in ComputedAttributesHandler.java that can result in Remote Co...
How severe is CVE-2018-1000881?
CVE-2018-1000881 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-1000881?
Check the references section above for vendor advisories and patch information. Affected products include: Traccar Server.