CVE-2016-1242
MEDIUMTryton <3.2.17, <3.4.14, <3.6.12, <3.8.8, <4.0.4 - Info Disclosure
Title source: llmDescription
file_open in Tryton before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allows remote authenticated users with certain permissions to read arbitrary files via the name parameter or unspecified other vectors.
Scores
CVSS v3
4.4
EPSS
0.0016
EPSS Percentile
37.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-200
Status
published
Affected Products (42)
tryton/tryton
tryton/tryton
tryton/tryton
tryton/tryton
tryton/tryton
< 3.2.16
tryton/tryton
tryton/tryton
tryton/tryton
tryton/tryton
tryton/tryton
tryton/tryton
tryton/tryton
tryton/tryton
tryton/tryton
tryton/tryton
... and 27 more
Timeline
Published
Sep 07, 2016
Tracked Since
Feb 18, 2026