Vulnonym.com

CVE-2012-0215 - Windowless Rushes

Description

model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model which allows remote authenticated users to modify the privileges of arbitrary users via a (1) create (2) write (3) delete or (4) copy rpc call.

Reference

http://www.debian.org/security/2012/dsa-2444 http://news.tryton.org/2012/03/security-releases-for-all-supported.html https://bugs.tryton.org/issue2476 http://hg.tryton.org/trytond/rev/8e64d52ecea4