Skip to main content
CRITICAL

CVE-2018-1000881

CVSS v3

9.8

CRITICAL

EPSS Score

8.0 %

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Traccar Traccar Server version 4.0 and earlier contains a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in ComputedAttributesHandler.java that can result in Remote Command Execution. This attack appear to be exploitable via Remote: web application request by a self-registered user. This vulnerability appears to have been fixed in 4.1 and later.

Technical details

Published
2018-12-20

Frequently asked questions

What is CVE-2018-1000881?

Traccar Traccar Server version 4.0 and earlier contains a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in ComputedAttributesHandler.java that can result in Remote Command Execution. This attack appear to be exploitable via Remote: web application request by a self-registered user. This vulnerability appears to have been fixed in 4.1 and later.

Is CVE-2018-1000881 actively exploited?

Active exploitation of CVE-2018-1000881 has not been confirmed. The EPSS score is 8.0%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2018-1000881?

CVE-2018-1000881 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2018-1000881 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key