GHSA-c8q5-2j73-qvcc
Dashboard / Vulnerabilities / GHSA-c8q5-2j73-qvcc
GHSA-c8q5-2j73-qvcc
Summary: trytond arbitrary fields write via a sequence of records
Details: `model/modelstorage.py` in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authenticated users to bypass intended access restrictions and write to arbitrary fields via a sequence of records.
References: https://nvd.nist.gov/vuln/detail/CVE-2015-0861, https://bugs.tryton.org/issue5167, https://foss.heptapod.net/tryton/tryton/-/commit/06230c381593c79766c4d8dcc92da3391e3acad2, https://github.com/pypa/advisory-database/tree/main/vulns/trytond/PYSEC-2016-11.yaml, https://github.com/tryton/trytond, http://www.debian.org/security/2015/dsa-3425, http://www.tryton.org/posts/security-release-for-issue5167.html
Affected packages
Package
Name: trytond
Purl: pkg:pypi/trytond
Affected ranges
Type: ECOSYSTEM
Events:
