Jaisurya has discovered that the content of the HTML editor was not escaped.
Impact
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: Required
- Scope: Changed
- Confidentiality: Low
- Integrity: Low
- Availability: None
Workaround
Setup restrictive CSP without unsafe inline script may prevent the attack.
Resolution
All affected users should upgrade trytond to the latest version.
Affected versions per series:
trytond:- 8.0: <= 8.0.10
- 7.8: <= 7.8.16
- 7.0: <= 7.0.57
Not affected versions per series:
trytond:- 8.0: >= 8.0.11
- 7.8: >= 7.8.17
- 7.0: >= 7.0.58
Reference
Concerns?
Any security concerns should be reported on the bug-tracker at https://bugs.tryton.org/ with the confidential checkbox checked.