Traccar – Unrestricted File Upload

ISGroup Cybersecurity

Traccar is a widely used open-source GPS tracking system that features a critical vulnerability in versions prior to 6.0 regarding path traversal and unrestricted file uploads. The system supports a large number of GPS devices, including those that send binary data instead of HTTP requests, making it very popular among users. This vulnerability allows attackers to create an account and exploit the flaw to upload files with the device. prefix into any directory. Risks include phishing attacks, cross-site scripting (XSS), and arbitrary command execution on the server. The issue has been fixed in version 6.0, and it is strongly recommended that users update the system.

ProductTraccar GPS
Date2024-08-27 08:49:16

Technical Summary

Traccar, a widely used open-source GPS tracking system, presents a critical vulnerability in versions prior to 6.0 involving path traversal and unrestricted file uploads. The system supports a high number of GPS devices, including those that send binary data instead of HTTP requests, a factor that fuels its popularity among users. Thanks to this vulnerability, an attacker can create an account and exploit the flaw to upload files with the device. prefix into any directory. The resulting risks include phishing attacks, cross-site scripting (XSS), and the potential for arbitrary command execution on the server. The issue has been resolved in version 6.0, and users are strongly advised to update the system.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert