Tryton

Trytond

6 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.48%
  • Published 10.03.2022 17:47:52
  • Last modified 21.11.2024 06:54:16

An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4, and ...

  • EPSS 5.59%
  • Published 10.03.2022 17:47:52
  • Last modified 21.11.2024 06:54:17

An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, ...

  • EPSS 0.35%
  • Published 21.11.2019 14:15:12
  • Last modified 21.11.2024 01:38:45

trytond 2.4: ModelView.button fails to validate authorization

  • EPSS 0.28%
  • Published 05.04.2019 01:29:00
  • Last modified 21.11.2024 04:20:00

In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6, an authenticated user can order records based on a field for which he has no access right. This may allow the...

Exploit
  • EPSS 0.25%
  • Published 13.04.2016 15:59:00
  • Last modified 12.04.2025 10:46:40

model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authenticated users to bypass intended access restrictions and write to arbitrary fields via a sequence of records.

Exploit
  • EPSS 0.62%
  • Published 12.07.2012 20:55:09
  • Last modified 11.04.2025 00:51:21

model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which allows remote authenticated users to modify the privileges of arbitrary ...