CVE-2018-1000881

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
20/12/2018
Last modified:
07/01/2019

Description

Traccar Traccar Server version 4.0 and earlier contains a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in ComputedAttributesHandler.java that can result in Remote Command Execution. This attack appear to be exploitable via Remote: web application request by a self-registered user. This vulnerability appears to have been fixed in 4.1 and later.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:traccar:server:*:*:*:*:*:*:*:* 4.0 (including)