5.5
CVSSv2

CVE-2012-0215

Published: 12/07/2012 Updated: 09/08/2012
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:P

Vulnerability Summary

model/modelstorage.py in the Tryton application framework (trytond) prior to 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which allows remote authenticated users to modify the privileges of arbitrary users via a (1) create, (2) write, (3) delete, or (4) copy rpc call.

Vulnerable Product Search on Vulmon Subscribe to Product

tryton trytond 2.0.5

tryton trytond 1.8.7

tryton trytond 1.4.13

tryton trytond 1.6.8

tryton trytond

Vendor Advisories

It was discovered that the Tryton application framework for Python allows authenticated users to escalate their privileges by editing the Many2Many field For the stable distribution (squeeze), this problem has been fixed in version 161-2+squeeze1 For the unstable distribution (sid), this problem has been fixed in version 222-1 We recommend t ...