// For flags

CVE-2012-0215

 

Severity Score

5.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which allows remote authenticated users to modify the privileges of arbitrary users via a (1) create, (2) write, (3) delete, or (4) copy rpc call.

model/modelstorage.py en el framework Tryton (trytond) anterior a v2.4.0 para Python no restringe correcteamente el acceso a el campo Many2Many en el modelo relacional, lo cual permite a usuarios remotos autenticados modificar los privilegios de usuarios arbitrarios mediante una llamada rpc (1) create, (2) write, (3) delete, or (4) copy.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
None
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2011-12-14 CVE Reserved
  • 2012-03-29 CVE Published
  • 2024-09-16 CVE Updated
  • 2024-09-16 First Exploit
  • 2024-09-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Tryton
Search vendor "Tryton"
Trytond
Search vendor "Tryton" for product "Trytond"
<= 2.2.3
Search vendor "Tryton" for product "Trytond" and version " <= 2.2.3"
-
Affected
Tryton
Search vendor "Tryton"
Trytond
Search vendor "Tryton" for product "Trytond"
1.4.13
Search vendor "Tryton" for product "Trytond" and version "1.4.13"
-
Affected
Tryton
Search vendor "Tryton"
Trytond
Search vendor "Tryton" for product "Trytond"
1.6.8
Search vendor "Tryton" for product "Trytond" and version "1.6.8"
-
Affected
Tryton
Search vendor "Tryton"
Trytond
Search vendor "Tryton" for product "Trytond"
1.8.7
Search vendor "Tryton" for product "Trytond" and version "1.8.7"
-
Affected
Tryton
Search vendor "Tryton"
Trytond
Search vendor "Tryton" for product "Trytond"
2.0.5
Search vendor "Tryton" for product "Trytond" and version "2.0.5"
-
Affected