Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-24809

Опубликовано: 10 апр. 2024
Источник: nvd
CVSS3: 8.5
EPSS Высокий

Описание

Traccar is an open source GPS tracking system. Versions prior to 6.0 are vulnerable to path traversal and unrestricted upload of file with dangerous type. Since the system allows registration by default, attackers can acquire ordinary user permissions by registering an account and exploit this vulnerability to upload files with the prefix device. under any folder. Attackers can use this vulnerability for phishing, cross-site scripting attacks, and potentially execute arbitrary commands on the server. Version 6.0 contains a patch for the issue.

EPSS

Процентиль: 100%
0.89894
Высокий

8.5 High

CVSS3

Дефекты

CWE-27

EPSS

Процентиль: 100%
0.89894
Высокий

8.5 High

CVSS3

Дефекты

CWE-27