Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-0861

Опубликовано: 13 апр. 2016
Источник: debian

Описание

model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authenticated users to bypass intended access restrictions and write to arbitrary fields via a sequence of records.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tryton-serverfixed3.8.1-1package
tryton-servernot-affectedwheezypackage
tryton-servernot-affectedsqueezepackage

Примечания

  • Mathias Behrle told us that affected versions are >= 3.2 and < 3.8.1

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 10 лет назад

model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authenticated users to bypass intended access restrictions and write to arbitrary fields via a sequence of records.

CVSS3: 4.3
nvd
почти 10 лет назад

model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authenticated users to bypass intended access restrictions and write to arbitrary fields via a sequence of records.

CVSS3: 4.3
github
больше 3 лет назад

trytond arbitrary fields write via a sequence of records