Security Release for issue 15032

Jaisurya has discovered that the content of the HTML editor was not escaped.

Impact

CVSS v3.0 Base Score: 5.4

  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: Required
  • Scope: Changed
  • Confidentiality: Low
  • Integrity: Low
  • Availability: None

Workaround

Setup restrictive CSP without unsafe inline script may prevent the attack.

Resolution

All affected users should upgrade trytond to the latest version.

Affected versions per series:

  • trytond:
    • 8.0: <= 8.0.10
    • 7.8: <= 7.8.16
    • 7.0: <= 7.0.57

Not affected versions per series:

  • trytond:
    • 8.0: >= 8.0.11
    • 7.8: >= 7.8.17
    • 7.0: >= 7.0.58

Reference

Concerns?

Any security concerns should be reported on the bug-tracker at https://bugs.tryton.org/ with the confidential checkbox checked.

1 Like