CVE-2016-1242
published 2016-09-07CVE-2016-1242: file_open in Tryton before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allows remote authenticated users with…
PriorityP427medium4.4CVSS 3.0
AVNACHPRHUINSUCHINAN
EPSS
1.82%
76.5th percentile
file_open in Tryton before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allows remote authenticated users with certain permissions to read arbitrary files via the name parameter or unspecified other vectors.
Affected
114 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tryton-server | < tryton-server 4.2.1-2 (bookworm) | tryton-server 4.2.1-2 (bookworm) |
| debian | tryton-server | < tryton-server 4.0.4-1 (bookworm) | tryton-server 4.0.4-1 (bookworm) |
| tryton | tryton | <= 3.2.16 | — |
| tryton | tryton | — | — |
| tryton | tryton | — | — |
| tryton | tryton | — | — |
| tryton | tryton | — | — |
| tryton | tryton | — | — |
| tryton | tryton | — | — |
| tryton | tryton | — | — |
| tryton | tryton | — | — |
| tryton | tryton | — | — |
| tryton | tryton | — | — |
| tryton | tryton | — | — |
| tryton | tryton | — | — |
| tryton | tryton | — | — |
| tryton | tryton | — | — |
| tryton | tryton | — | — |
| tryton | tryton | — | — |
| tryton | tryton | — | — |
| tryton | tryton | — | — |
| tryton | tryton | — | — |
| tryton | tryton | — | — |
| tryton | tryton | — | — |
| tryton | tryton | — | — |
CVSS provenance
nvdv3.04.4MEDIUMCVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
ghsa4.4MEDIUM
osv4.4MEDIUM
vendor_debian4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2017-0360: tryton-server - file_open in Tryton 3.x and 4.x through 4.2.2 allows remote authenticated users ...
vendor_debian·2017·CVSS 4.4
CVE-2017-0360 [MEDIUM] CVE-2017-0360: tryton-server - file_open in Tryton 3.x and 4.x through 4.2.2 allows remote authenticated users ...
file_open in Tryton 3.x and 4.x through 4.2.2 allows remote authenticated users with certain permissions to read arbitrary files via a "same root name but with a suffix" attack. NOTE: This vulnerability exists because of an incomplete fix for CVE-2016-1242.
Scope: local
bookworm: resolved (fixed in 4.2.1-2)
bullseye: resolved (fixed in 4.2.1-2)
forky: resolved (fixed in 4.2.1-2)
sid: resolved (fixed in 4.2.1-2)
trixie: resolved (fixed in 4.2.1-2)
Debian
CVE-2016-1242: tryton-server - file_open in Tryton before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8...
vendor_debian·2016·CVSS 4.4
CVE-2016-1242 [MEDIUM] CVE-2016-1242: tryton-server - file_open in Tryton before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8...
file_open in Tryton before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allows remote authenticated users with certain permissions to read arbitrary files via the name parameter or unspecified other vectors.
Scope: local
bookworm: resolved (fixed in 4.0.4-1)
bullseye: resolved (fixed in 4.0.4-1)
forky: resolved (fixed in 4.0.4-1)
sid: resolved (fixed in 4.0.4-1)
trixie: resolved (fixed in 4.0.4-1)
GHSA
Tryton allow authenticated users with certain permissions to read arbitrary files via the name parameter
ghsa·2022-05-17
CVE-2016-1242 [MEDIUM] CWE-200 Tryton allow authenticated users with certain permissions to read arbitrary files via the name parameter
Tryton allow authenticated users with certain permissions to read arbitrary files via the name parameter
`file_open` in Tryton before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allows remote authenticated users with certain permissions to read arbitrary files via the name parameter or unspecified other vectors.
OSV
Tryton allow authenticated users with certain permissions to read arbitrary files via the name parameter
osv·2022-05-17
CVE-2016-1242 [MEDIUM] Tryton allow authenticated users with certain permissions to read arbitrary files via the name parameter
Tryton allow authenticated users with certain permissions to read arbitrary files via the name parameter
`file_open` in Tryton before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allows remote authenticated users with certain permissions to read arbitrary files via the name parameter or unspecified other vectors.
OSV
Tryton Information Disclosure Vulnerability
osv·2022-05-13·CVSS 4.4
CVE-2017-0360 [MEDIUM] Tryton Information Disclosure Vulnerability
Tryton Information Disclosure Vulnerability
file_open in Tryton 3.x and 4.x through 4.2.2 allows remote authenticated users with certain permissions to read arbitrary files via a "same root name but with a suffix" attack. NOTE: This vulnerability exists because of an incomplete fix for CVE-2016-1242.
GHSA
Tryton Information Disclosure Vulnerability
ghsa·2022-05-13·CVSS 4.4
CVE-2017-0360 [MEDIUM] CWE-269 Tryton Information Disclosure Vulnerability
Tryton Information Disclosure Vulnerability
file_open in Tryton 3.x and 4.x through 4.2.2 allows remote authenticated users with certain permissions to read arbitrary files via a "same root name but with a suffix" attack. NOTE: This vulnerability exists because of an incomplete fix for CVE-2016-1242.
OSV
CVE-2017-0360: file_open in Tryton 3
osv·2017-04-04·CVSS 4.4
CVE-2017-0360 [MEDIUM] CVE-2017-0360: file_open in Tryton 3
file_open in Tryton 3.x and 4.x through 4.2.2 allows remote authenticated users with certain permissions to read arbitrary files via a "same root name but with a suffix" attack. NOTE: This vulnerability exists because of an incomplete fix for CVE-2016-1242.
OSV
CVE-2016-1242: file_open in Tryton before 3
osv·2016-09-07·CVSS 4.4
CVE-2016-1242 [MEDIUM] CVE-2016-1242: file_open in Tryton before 3
file_open in Tryton before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allows remote authenticated users with certain permissions to read arbitrary files via the name parameter or unspecified other vectors.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2020-37014 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2020-37014 [HIGH] CVE-2020-37014 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2020-37014 :
Tryton vulnerability analysis and mitigation
Tryton 5.4 contains a persistent cross-site scripting vulnerability in the user profile name input that allows remote attackers to inject malicious scripts. Attackers can exploit the vulnerability by inserting script payloads in the name field, which execute in the frontend and backend user interfaces.
Source : NVD
## 5.1
Score
Published January 30, 2026
Severity MEDIUM
CNA Score 5.1
Affected Technologies
Tryton
Linux Debian
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 17.8
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
tryton-sao
cpe:2.3:a:tryton:tryton
Sources
NVD
Debian 12, 13, 14 Sever
Bugzilla
CVE-2017-0360 tryton: file_open does not sanitize all cases
bugzilla·2017-04-05·CVSS 4.4
CVE-2017-0360 [MEDIUM] CVE-2017-0360 tryton: file_open does not sanitize all cases
CVE-2017-0360 tryton: file_open does not sanitize all cases
A vulnerability was found in tryton that allows an authenticated user with write access to report or icon definition to make the server open any readable file under any sibling folder of the trytond installation but only if starts with trytond (for example: ../trytond_suffix). This is a remaining case from CVE-2016-1242
External References:
http://www.tryton.org/ca/posts/security-release-for-issue6361.html
Upstream bug:
https://bugs.tryton.org/issue6361
Discussion:
Created tryton tracking bugs for this issue:
Affects: epel-6 [bug 1439093]
Affects: fedora-all [bug 1439092]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat pr
Bugzilla
CVE-2016-1242 tryton: admin user able to access all files on system
bugzilla·2016-09-08·CVSS 4.4
CVE-2016-1242 [MEDIUM] CVE-2016-1242 tryton: admin user able to access all files on system
CVE-2016-1242 tryton: admin user able to access all files on system
A flaw in trytond has been discovered:
The CVE-2016-1242 allows an authenticated user with write access to access any readable file on the system. By default, only the administrator group has such right access.
Upstream bug:
https://bugs.tryton.org/issue5808
Discussion:
Created tryton tracking bugs for this issue:
Affects: fedora-all [bug 1374221]
Affects: epel-all [bug 1374222]
---
python-proteus-4.0.2-1.fc25, tryton-4.0.4-1.fc25, trytond-4.0.4-1.fc25, trytond-account-4.0.3-1.fc25, trytond-account-invoice-4.0.2-1.fc25, trytond-account-product-4.0.2-1.fc25, trytond-account-statement-4.0.2-1.fc25, trytond-company-4.0.3-1.fc25, trytond-google-maps-4.0.2-1.fc25, trytond-party-4.0.2-1.fc25, trytond-purchase-4.0.3-1.fc
Bugzilla
CVE-2016-1241 CVE-2016-1242 tryton: various flaws [epel-all]
bugzilla·2016-09-08·CVSS 5.3
CVE-2016-1241 [MEDIUM] CVE-2016-1241 CVE-2016-1242 tryton: various flaws [epel-all]
CVE-2016-1241 CVE-2016-1242 tryton: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora EPEL.
Bugzilla
CVE-2016-1241 CVE-2016-1242 tryton: various flaws [fedora-all]
bugzilla·2016-09-08·CVSS 5.3
CVE-2016-1241 [MEDIUM] CVE-2016-1241 CVE-2016-1242 tryton: various flaws [fedora-all]
CVE-2016-1241 CVE-2016-1242 tryton: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While o
http://www.debian.org/security/2016/dsa-3656http://www.tryton.org/posts/security-release-for-issue5795-and-issue5808.htmlhttps://bugs.tryton.org/issue5808http://www.debian.org/security/2016/dsa-3656http://www.tryton.org/posts/security-release-for-issue5795-and-issue5808.htmlhttps://bugs.tryton.org/issue5808
2016-09-07
Published