CVE-2012-0215
Tryton trytond < 2.4.0 - Authenticated Privilege Escalation via Many2Many Field Manipulation
Title source: llmDescription
model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which allows remote authenticated users to modify the privileges of arbitrary users via a (1) create, (2) write, (3) delete, or (4) copy rpc call.
References (4)
Core 4
Core References
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2012/dsa-2444
Various Sources x_refsource_confirm
https://bugs.tryton.org/issue2476
Exploit, Patch x_refsource_confirm
http://hg.tryton.org/trytond/rev/8e64d52ecea4
Vendor Advisory x_refsource_confirm
http://news.tryton.org/2012/03/security-releases-for-all-supported.html
Scores
EPSS
0.0197
EPSS Percentile
78.3%
Details
CWE
CWE-264
Status
published
Products (6)
pypi/trytond
0 - 2.4.0PyPI
tryton/trytond
1.4.13
tryton/trytond
1.6.8
tryton/trytond
1.8.7
tryton/trytond
2.0.5
tryton/trytond
< 2.2.3
Published
Jul 12, 2012
Tracked Since
Feb 18, 2026