CVE-2018-1000881: Code Injection
Traccar Traccar Server version 4.0 and earlier contains a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in ComputedAttributesHandler.java that can result in Remote Command Execution. This attack appear to be exploitable via Remote: web application request by a self-registered user. This vulnerability appears to have been fixed in 4.1 and later.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-1000881?
CVE-2018-1000881 is a vulnerability in Traccar Server version 4.0 and earlier that allows remote code execution through improper control of code generation.
How severe is CVE-2018-1000881?
CVE-2018-1000881 has a severity of 9.8 (Critical).
What software is affected by CVE-2018-1000881?
Traccar Server version 4.0 and earlier is affected by CVE-2018-1000881.
How can CVE-2018-1000881 be exploited?
CVE-2018-1000881 can be exploited via a remote web application request, allowing for remote command execution.