6.5 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): REQUIRED
- Scope (S): CHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): LOW
- Availability impact (A): LOW
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
7 packages
- python312Packages.pytraccar
- python313Packages.pytraccar
- python314Packages.pytraccar
- home-assistant-component-tests.traccar
- tests.home-assistant-components.traccar
- home-assistant-component-tests.traccar_server
- tests.home-assistant-components.traccar_server
- @LeSuisse ignored reference https://g…
- @LeSuisse accepted
traccar allows CSV formula injection via exported position data
Traccar is an open source GPS tracking system. In versions between 6.11.1 and 6.13.0, the CSV export functionality writes position data, including user-controlled device and computed attributes, to CSV output without proper escaping. An attacker can inject spreadsheet formulas through exported fields. When a manager or administrator opens the exported CSV file in spreadsheet software, this can cause formula execution and lead to command execution or data exfiltration. This has been patched in version 6.13.0.
References
-
https://github.com/traccar/traccar/security/advisories/GHSA-745r-9qgj-x7m7 x_refsource_CONFIRMexploit
Ignored references (1)
Affected products
- ==>= 6.11.1 , < 6.13.0
Matching in nixpkgs
Ignored packages (7)
pkgs.python312Packages.pytraccar
Python library to handle device information from Traccar
pkgs.python313Packages.pytraccar
Python library to handle device information from Traccar
pkgs.python314Packages.pytraccar
Python library to handle device information from Traccar
pkgs.home-assistant-component-tests.traccar
Open source home automation that puts local control and privacy first
pkgs.tests.home-assistant-components.traccar
Open source home automation that puts local control and privacy first
pkgs.home-assistant-component-tests.traccar_server
Open source home automation that puts local control and privacy first
pkgs.tests.home-assistant-components.traccar_server
Open source home automation that puts local control and privacy first
Package maintainers
-
@frederictobiasc Frédéric Christ <dev@ntr.li>