Vulnerabilities (CVE)

Filtered by vendor Tryton Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2012-2238 1 Tryton 1 Trytond 2019-11-22 5.0 MEDIUM 7.5 HIGH
trytond 2.4: ModelView.button fails to validate authorization
CVE-2014-6633 1 Tryton 1 Tryton 2018-05-22 9.0 HIGH 8.8 HIGH
The safe_eval function in trytond in Tryton before 2.4.15, 2.6.x before 2.6.14, 2.8.x before 2.8.11, 3.0.x before 3.0.7, and 3.2.x before 3.2.3 allows remote authenticated users to execute arbitrary commands via shell metacharacters in (1) the collection.domain in the webdav module or (2) the formula field in the price_list module.