Description
model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authenticated users to bypass intended access restrictions and write to arbitrary fields via a sequence of records.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-3425-1 | tryton-server security update |
EUVD |
EUVD-2016-0038 | model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authenticated users to bypass intended access restrictions and write to arbitrary fields via a sequence of records. |
Github GHSA |
GHSA-c8q5-2j73-qvcc | trytond arbitrary fields write via a sequence of records |
References
History
No history.
Status: PUBLISHED
Assigner: debian
Published:
Updated: 2024-08-06T04:26:10.389Z
Reserved: 2015-01-07T00:00:00.000Z
Link: CVE-2015-0861
No data.
Status : Modified
Published: 2016-04-13T15:59:00.133
Modified: 2026-05-06T22:30:45.220
Link: CVE-2015-0861
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Github GHSA