4
CVSSv2

CVE-2015-0861

Published: 13/04/2016 Updated: 01/02/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

model/modelstorage.py in trytond 3.2.x prior to 3.2.10, 3.4.x prior to 3.4.8, 3.6.x prior to 3.6.5, and 3.8.x prior to 3.8.1 allows remote authenticated users to bypass intended access restrictions and write to arbitrary fields via a sequence of records.

Vulnerable Product Search on Vulmon Subscribe to Product

tryton trytond

debian debian linux 8.0

Vendor Advisories

Cédric Krier discovered a vulnerability in the server-side of Tryton, an application framework written in Python An authenticated malicious user can write arbitrary values in record fields due missed checks of access permissions when multiple records are written The oldstable distribution (wheezy) is not affected For the stable distribution (je ...