PT-2026-95061 · Traccar · Traccar
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:S/C:C/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Traccar versions prior to 6.14.0
Description
An authenticated, non-readonly user can exploit a flaw when submitting requests to the 'DELETE /api/permissions' endpoint. The
Permission(LinkedHashMap<String, Long>) function in src/main/java/org/traccar/model/Permission.java only validates the first two keys of the provided JSON, while the DatabaseStorage.removePermission() function in src/main/java/org/traccar/storage/DatabaseStorage.java concatenates all map keys into the SQL WHERE clause as column identifiers. This allows an attacker to inject controlled SQL via an extra JSON key, creating a blind boolean or error oracle. This can be used to extract sensitive database values, such as administrator emails, password hashes, and salts, or to conditionally delete permission rows.Recommendations
Update to version 6.14.0.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Traccar