CVE-2015-0861: Medium severity tryton vulnerability
model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authenticated users to bypass intended access restrictions and write to arbitrary fields via a sequence of records.
Other sources
model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authenticated users to bypass intended access restrictions and write to arbitrary fields via a sequence of records.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0861?
The severity of CVE-2015-0861 is considered to be moderate due to its ability to allow remote authenticated users to bypass access restrictions.
How do I fix CVE-2015-0861?
To fix CVE-2015-0861, upgrade your version of trytond to at least 3.2.10, 3.4.8, 3.6.5, or 3.8.1 depending on your current version.
Which versions are affected by CVE-2015-0861?
CVE-2015-0861 affects trytond versions 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1.
What types of users are impacted by CVE-2015-0861?
Remote authenticated users are the ones impacted by CVE-2015-0861 as they can manipulate fields improperly.
Is there a known exploit for CVE-2015-0861?
There are no known exploits publicly available for CVE-2015-0861, but the nature of the vulnerability suggests it could be exploited by authenticated users.