CVE-2020-5246: LDAP injection vulnerability in Traccar GPS Tracking System
Traccar GPS Tracking System before version 4.9 has a LDAP injection vulnerability. It occurs when user input is being used in LDAP search filter. By providing specially crafted input, an attacker can modify the logic of the LDAP query and get admin privileges. The issue only impacts instances with LDAP configuration and where users can craft their own names. This has been patched in version 4.9.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5246?
The severity of CVE-2020-5246 is rated as high with a CVSS score of 6.5.
How does the LDAP injection vulnerability in CVE-2020-5246 occur?
The LDAP injection vulnerability in CVE-2020-5246 occurs when user input is used in an LDAP search filter, allowing attackers to modify the logic of the LDAP query and gain admin privileges.
Is Traccar GPS Tracking System version 4.9 affected by CVE-2020-5246?
Yes, Traccar GPS Tracking System before version 4.9 is affected by the LDAP injection vulnerability CVE-2020-5246.