CVE-2020-5246: LDAP injection vulnerability in Traccar GPS Tracking System

Published Jul 14, 2020
·
Updated

Traccar GPS Tracking System before version 4.9 has a LDAP injection vulnerability. It occurs when user input is being used in LDAP search filter. By providing specially crafted input, an attacker can modify the logic of the LDAP query and get admin privileges. The issue only impacts instances with LDAP configuration and where users can craft their own names. This has been patched in version 4.9.

Affected Software

1 affected component
Traccar Traccar<4.9

Event History

Jul 14, 2020
CVE Published
via MITRE·08:42 PM
Data Sourced
via MITRE·08:42 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2020-5246?

The severity of CVE-2020-5246 is rated as high with a CVSS score of 6.5.

2

How does the LDAP injection vulnerability in CVE-2020-5246 occur?

The LDAP injection vulnerability in CVE-2020-5246 occurs when user input is used in an LDAP search filter, allowing attackers to modify the logic of the LDAP query and gain admin privileges.

3

Is Traccar GPS Tracking System version 4.9 affected by CVE-2020-5246?

Yes, Traccar GPS Tracking System before version 4.9 is affected by the LDAP injection vulnerability CVE-2020-5246.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203