VYPR
Critical severity9.8NVD Advisory· Published Dec 20, 2018· Updated Jun 17, 2026

CVE-2018-1000881

CVE-2018-1000881

Description

Traccar Traccar Server version 4.0 and earlier contains a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in ComputedAttributesHandler.java that can result in Remote Command Execution. This attack appear to be exploitable via Remote: web application request by a self-registered user. This vulnerability appears to have been fixed in 4.1 and later.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Range: >=4.1
  • Traccar/Server2 versions
    cpe:2.3:a:traccar:server:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:traccar:server:*:*:*:*:*:*:*:*range: <=4.0
    • (no CPE)range: <=4.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.