Impact
Authenticated users with permission editing capabilities can craft a DELETE /api/permissions request containing an extra JSON key. The application validates only the first two keys, but the underlying storage code concatenates every map key into the SQL WHERE clause, turning the attacker-controlled key into arbitrary SQL. This results in a blind boolean or error oracle against the database, from which an attacker can retrieve values such as administrator email addresses, password hashes, and salts, or cause selective deletion of permission rows. The flaw does not provide remote code execution but permits significant data exfiltration and privilege manipulation.
Affected Systems
The affected product is Traccar GPS tracking software, versions prior to 6.14.0. Users running any release older than 6.14.0 who possess non‑readonly permission editing privileges are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium to high severity with significant impact on confidentiality and integrity. The EPSS score of less than 1% suggests a very low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authentication and a valid permission‑management session, so the attack vector is through authenticated API usage. If an attacker gains or hijacks a legitimate account with sufficient privileges, the blind oracle can be leveraged to enumerate database contents or delete permissions, potentially compromising the entire system. The risk remains moderate due to the adherence to authentication but high due to the depth of data that can be extracted once access is achieved.
OpenCVE Enrichment