CVE-2022-26661
- EPSS 0.48%
- Veröffentlicht 10.03.2022 17:47:52
- Zuletzt bearbeitet 21.11.2024 06:54:16
An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4, and ...
CVE-2022-26662
- EPSS 5.59%
- Veröffentlicht 10.03.2022 17:47:52
- Zuletzt bearbeitet 21.11.2024 06:54:17
An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, ...
CVE-2012-2238
- EPSS 0.35%
- Veröffentlicht 21.11.2019 14:15:12
- Zuletzt bearbeitet 21.11.2024 01:38:45
trytond 2.4: ModelView.button fails to validate authorization
CVE-2019-10868
- EPSS 0.28%
- Veröffentlicht 05.04.2019 01:29:00
- Zuletzt bearbeitet 21.11.2024 04:20:00
In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6, an authenticated user can order records based on a field for which he has no access right. This may allow the...
CVE-2015-0861
- EPSS 0.25%
- Veröffentlicht 13.04.2016 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authenticated users to bypass intended access restrictions and write to arbitrary fields via a sequence of records.
CVE-2012-0215
- EPSS 0.62%
- Veröffentlicht 12.07.2012 20:55:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which allows remote authenticated users to modify the privileges of arbitrary ...