Skip to content

Commit

Permalink
Update CVE-2024-24809.yaml
Browse files Browse the repository at this point in the history
  • Loading branch information
ritikchaddha authored Aug 24, 2024
1 parent 14c1304 commit 0ceb423
Showing 1 changed file with 2 additions and 1 deletion.
3 changes: 2 additions & 1 deletion http/cves/2024/CVE-2024-24809.yaml
Original file line number Diff line number Diff line change
@@ -1,14 +1,15 @@
id: CVE-2024-24809

info:
name: Traccar - Unrestricted Upload of File with Dangerous Type
name: Traccar - Unrestricted File Upload
author: DhiyaneshDK
severity: high
description: |
Traccar is an open source GPS tracking system. Versions prior to 6.0 are vulnerable to path traversal and unrestricted upload of file with dangerous type. Since the system allows registration by default, attackers can acquire ordinary user permissions by registering an account and exploit this vulnerability to upload files with the prefix `device.` under any folder. Attackers can use this vulnerability for phishing, cross-site scripting attacks, and potentially execute arbitrary commands on the server. Version 6.0 contains a patch for the issue.
reference:
- https://github.com/traccar/traccar/commit/b099b298f90074c825ba68ce73532933c7b9d901
- https://github.com/traccar/traccar/security/advisories/GHSA-vhrw-72f6-gwp5
- https://nvd.nist.gov/vuln/detail/CVE-2024-24809
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L
cvss-score: 8.5
Expand Down

0 comments on commit 0ceb423

Please sign in to comment.