CVE-2025-66422
- EPSS 0.04%
- Veröffentlicht 30.11.2025 00:00:00
- Zuletzt bearbeitet 04.12.2025 17:11:09
Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.
CVE-2025-66423
- EPSS 0.03%
- Veröffentlicht 30.11.2025 00:00:00
- Zuletzt bearbeitet 04.12.2025 17:10:35
Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.
CVE-2025-66424
- EPSS 0.03%
- Veröffentlicht 30.11.2025 00:00:00
- Zuletzt bearbeitet 04.12.2025 16:50:12
Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.
CVE-2022-26661
- EPSS 0.48%
- Veröffentlicht 10.03.2022 17:47:52
- Zuletzt bearbeitet 21.11.2024 06:54:16
An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4, and ...
CVE-2022-26662
- EPSS 5.59%
- Veröffentlicht 10.03.2022 17:47:52
- Zuletzt bearbeitet 21.11.2024 06:54:17
An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, ...
CVE-2012-2238
- EPSS 0.35%
- Veröffentlicht 21.11.2019 14:15:12
- Zuletzt bearbeitet 21.11.2024 01:38:45
trytond 2.4: ModelView.button fails to validate authorization
CVE-2019-10868
- EPSS 0.28%
- Veröffentlicht 05.04.2019 01:29:00
- Zuletzt bearbeitet 21.11.2024 04:20:00
In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6, an authenticated user can order records based on a field for which he has no access right. This may allow the...
CVE-2015-0861
- EPSS 0.25%
- Veröffentlicht 13.04.2016 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authenticated users to bypass intended access restrictions and write to arbitrary fields via a sequence of records.
CVE-2012-0215
- EPSS 0.62%
- Veröffentlicht 12.07.2012 20:55:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which allows remote authenticated users to modify the privileges of arbitrary ...