CVE-2024-31214
Last modified
CVE-2024-31214 is a critical-severity vulnerability rated 9.6/10 on the CVSS scale. Traccar is an open source GPS tracking system. Traccar versions 5.1 through 5.12 allow arbitrary files to be uploaded through the device image upload API. EPSS estimates a 17.63% chance of exploitation in the next 30 days.
Description
Traccar is an open source GPS tracking system. Traccar versions 5.1 through 5.12 allow arbitrary files to be uploaded through the device image upload API. Attackers have full control over the file contents, full control over the directory where the file is stored, full control over the file extension, and partial control over the file name. While it's not for an attacker to overwrite an existing file, an attacker can create new files with certain names and attacker-controlled extensions anywhere on the file system. This can potentially lead to remote code execution, XSS, DOS, etc. The default install of Traccar makes this vulnerability more severe. Self-registration is enabled by default, allowing anyone to create an account to exploit this vulnerability. Traccar also runs by default with root/system privileges, allowing files to be placed anywhere on the file system. Version 6.0 contains a fix for the issue. One may also turn off self-registration by default, as that would make most vulnerabilities in the application much harder to exploit by default and reduce the severity considerably.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Traccar | Traccar | >= 5.1, <= 5.12 |
References
- https://github.com/traccar/traccar/security/advisories/GHSA-3gxq-f2qj-c8v9Exploit, Vendor Advisory
- https://github.com/traccar/traccar/security/advisories/GHSA-3gxq-f2qj-c8v9Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-31214?
How severe is CVE-2024-31214?
How do I fix CVE-2024-31214?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-31209oidcc is the OpenID Connect client library for Erlang. Denia…5.3
- CVE-2024-3121A remote code execution vulnerability exists in the create_c…3.3
- CVE-2024-31210WordPress is an open publishing platform for the Web. It's p…8.8
- CVE-2024-31211WordPress is an open publishing platform for the Web. Unseri…9.8
- CVE-2024-31212InstantCMS is a free and open source content management syst…7.2
- CVE-2024-31213InstantCMS is a free and open source content management syst…5.4
- CVE-2024-31215Mobile Security Framework (MobSF) is a security research pla…4.3
- CVE-2024-31216The source-controller is a Kubernetes operator, specialised …5.1
- CVE-2024-31217Strapi is an open-source content management system. Prior to…6.5
- CVE-2024-31218Webhood is a self-hosted URL scanner used analyzing phishing…9.8
- CVE-2024-31219Discourse-reactions is a plugin that allows user to add thei…4.3
- CVE-2024-3122CHANGING Mobile One Time Password does not properly filter p…4.9
Are you affected by CVE-2024-31214?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
