PT-2016-3567 · Tryton · Tryton

Cédric Krier

·

Published

2015-12-17

·

Updated

2022-05-14

·

CVE-2015-0861

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions trytond versions 3.2.x through 3.2.9 trytond versions 3.4.x through 3.4.7 trytond versions 3.6.x through 3.6.4 trytond versions 3.8.x through 3.8.0
Description The issue allows remote authenticated users to bypass intended access restrictions and write to arbitrary fields via a sequence of records.
Recommendations For trytond versions 3.2.x through 3.2.9, update to version 3.2.10 or later. For trytond versions 3.4.x through 3.4.7, update to version 3.4.8 or later. For trytond versions 3.6.x through 3.6.4, update to version 3.6.5 or later. For trytond versions 3.8.x through 3.8.0, update to version 3.8.1 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-0861
DSA-3425-1
GHSA-C8Q5-2J73-QVCC
PYSEC-2016-11

Affected Products

Tryton