CVE-2012-0215

Tryton trytond < 2.4.0 - Authenticated Privilege Escalation via Many2Many Field Manipulation

Title source: llm
STIX 2.1

Description

model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which allows remote authenticated users to modify the privileges of arbitrary users via a (1) create, (2) write, (3) delete, or (4) copy rpc call.

References (4)

Core 4
Core References
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2012/dsa-2444
Various Sources x_refsource_confirm
https://bugs.tryton.org/issue2476
Exploit, Patch x_refsource_confirm
http://hg.tryton.org/trytond/rev/8e64d52ecea4

Scores

EPSS 0.0197
EPSS Percentile 78.3%

Details

CWE
CWE-264
Status published
Products (6)
pypi/trytond 0 - 2.4.0PyPI
tryton/trytond 1.4.13
tryton/trytond 1.6.8
tryton/trytond 1.8.7
tryton/trytond 2.0.5
tryton/trytond < 2.2.3
Published Jul 12, 2012
Tracked Since Feb 18, 2026