cbcvebase.
CVE-2012-0215
published 2012-07-12

CVE-2012-0215: model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the…

PriorityP429medium5.5CVSS 2.0
AVNACLAuSCNIPAP
EPSS
1.97%
78.3th percentile
model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which allows remote authenticated users to modify the privileges of arbitrary users via a (1) create, (2) write, (3) delete, or (4) copy rpc call.

Affected

7 ranges
VendorProductVersion rangeFixed in
debiantryton-server< tryton-server 2.2.2-1 (bookworm)tryton-server 2.2.2-1 (bookworm)
trytontrytond<= 2.2.3
trytontrytond
trytontrytond
trytontrytond
trytontrytond
trytontrytond>= 0 < 2.4.02.4.0

CVSS provenance

nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.